I am writing Pl/SQL and in my code I build a SQL statement out of parmeters passed to my code I MUST be aware of a MAJOR issue If I build a SQL statment out of UN-TRUSTED paramaters I am subject to a SQL Injection Attack