After reading this I can safely say that the quote below is in fact true
(explanation of the kind of attacks you're talking about below, I'm assuming you know basic SQL, used PHP bc its the only language thats supported by the code blocks on here)
The way these attacks used to work in the past...