This 17 minute demo really shows what you can do with a sql injection attack. It goes far behind just pulling private data from the database.
Good stuff!
No Comments