8.3.3 allows SQL Injection