A comprehensive guide to bWAPP, a deliberately insecure web application designed to teach over 100 different web vulnerabilities. [Sql-injection (search/get + stored/blog + Csrf change password)]
Open Web Application Security Project (OWASP) Broken Web Applications Project, a collection of vulnerable web applications that is distributed on a Virtual Machine in Vmware.
Understanding the fundamentals of SQL injection attacks and exploitation techniques.