Characters written into an input form are treated as part of a command to the database. This is the basis of SQL injection.