http://example.com/lists/admin/?page...1/*sp_password

Although not completely open because one must authenticate, but completely leaves the database open.. thus being a SQL Injection hole.