My employer is looking at purchasing ADSelfService Plus, but is concerned about protection against SQL Injection on the MySQL db. Can anyone confirm whether or not the MySQL db will pass commands from the web application (i.e. special characters used in db queries) to the database without checking the input?