Check out this ISC article concerning a new SQL injection attack that is happening to many website running Microsoft SQL Server.
http://isc.sans.edu/diary.html?storyid=12127
While using Linux is not a guaranteed protection from this sort of attack, it does show how easy sites can be compromised that don’t do proper URL filtering.
