I accidentally SQL injected phpBB without even trying. Registered user "*" (just the asterisk), searching posts for * resulted in a list of everyones post together. Fun times.