On October 15, 2014 the Drupal security team announced the worst SQL injection vulnerability in the history of Drupal https://www.drupal.org/SA-CORE-2014-005. In this video, I explain how the flaw worked, and how it can be used to very easily to inject SQL into your Drupal site, even by someone with zero programing knowledge.