I've been keeping a casual eye on sql injection stuff, and unicode escaping seems to be a source of problems.