SQL injection attack -- what to do?

I’ve been receiving a number of spammy submissions that appear to be an attempt at SQL injection. At least that’s what it looks like – SQL commands submitted via my form.

Am I at risk for an imment hack? What should I be doing?

These seem to be sporadic and come in waves – I’ll get 50-60 submissions with various SQL commands. Then it goes away for a few weeks.

