First of all, welcome to GSO.
Secondly, a good tip would be to "look before you ask". This isnt just a forum, there are tons upon tons of articles, guides and other information at the main page (
http://www.governmentsecurity.org)
There is also a handy search function there too....just type in what you need and it will find it for you.
Apart from all that, SQL (exploits??) is covered indepth in numerous posts in this forum.
Search the two, and you should find what your looking for.
Hope this helps.