SQL Injection via table names and field names. Case study.
renesd.blogspot.com
renesd.blogspot.com
This is the reason you don't use a web-interface to do this. Allowing admin-level traffic to enter through the same channels as user traffic is generally a bad idea.
It's a major hole to an important layer in your defenses. Opening it up and you ask for trouble... even if you establish permissions, those can be bypassed with escalation exploits.
Some input really is trusted.