By entering certain strings of text into user input boxes on Web sites, cybercriminals are able to confuse their commands with data in a site's Structured Query Language (SQL) database and gain control of it, says Grossman.
FORBES: Google-Hacking Goes To China