SQL injection is a way of using Forms or what ever in HTML/PHP to execute SQL. So you would do like in a password feild
);// to kill the last paswordstatement
password,null); CREATE_NEW_TABLE(THIS,THAT, THEOTHER);
Like ending the SQL Statement within the statement and adding another line to the code that shouldnt be there.
It's easy... use Metasploid and Kali Linux, it'l pretty much do it for u.