Just seen in my code base: a developer parameterized "now()" (rather than just use SQL's "getDate()") but not an untrusted variable