Even if characters other than alphabets and numbers are not allowed on client-side, the attacker might intercept the HTTP traffic between the browser and the server with the help of tools like TamperIE, Fiddler etc and insert the special characters that were prevented in the client-side validation.