Its an attack in which we use specially crafted SQL quereis to carry out malicious activites on the target system.
This vulnerability exists due to a lack of validation of input when a database query is made on internet.
The best part about SQL injection attacks can be executed with the help of only a browser
Here we had login through the admin page by using the following details
username: admin
password:'or''=' (default)
when u login to the admin page the whole website is under ur control and by simple programming u can just change everything