I'm amazed SQL injection attacks have the level of prominence, and are as common as they appear to be, in the field of web security. Anyone with more then just a cursory understanding of web development should be protecting their commands.
It seems to me like it might be wise to have a standardized qualifications test for the web - something that tells employers "this guy won't put security holes in my program"