You probably know this, (at least I hope you know this), and your example was only for illustration purposes.
A statement like
leaves you open to a SQL injection attack. What will happen if the username entered by your user is something like the following?
I hope I'm not stating the obvious.