I was wondering if allowing " and \ in the username or password field would cause SQL injection. Could somebody explain me this one and tell me what does magicquotes do?

Thanks a lot in advance...