Security. Most devs couldn't care less about the security of the applications they develop. SQL straight to the database? Hold my beer.
Sending strings with shell commands and allowing arbitrary code execution? Can't see where this should go wrong.

