eClinicalWorks interview question

mostly on sql injection