I doubt it is 'someone' as much as it is 'some bot' searching for sql vulnerabilities. We occasionally notice a similar thing with a a bunch of visits to a page with attempted sql injection in the query string. As long as your inputs are sanitized (and you arent returning details on errors) you shouldn't have a problem.