How do you completely compromise a machine given a text box or badly validated input box? This is a place to talk about code issues (PHP includes, null byte injection, backticks, pipe, etc...) as well as how to properly construct an SQL injection attack.
LOL buddy start studing mysql.see the inbuilt functions.
->database() = shows name of the database.
->version or @@version = shows version.
->user() = local or remote user identity
->@@basedir = directory
->@datadir = work the same shows mysql dir