Recently my site was hacked via SQL injection. The hacker used the following query to get my DB name. I cannot understand this query they wrote.
Query:
-999.9 UNION ALL SELECT CONCAT('Hex(cast(database() as char))'), 0x31303235343830303536, 0x31303235343830303536, 0x31303235343830303536
I think you must have other entries in your log, if not he knew before hand that you have 3 columns.