CREATE TABLE user_value
(`user_name` varchar(4), `user_pass` varchar(3))
;
select * from user_value;
select * from user_value WHERE user_name='admin_email\' AND (SELECT CASE WHEN (SUBSTRING(admin_pass,1,1) = \'a\') THEN SLEEP(5) ELSE 1 END) AND \'1\' = \'1' AND user_pass='pass\' --'
<?php
$q = mysqli_prepare(
$mysqli,
"INSERT INTO `user_value` (`user_name`, `user_pass`) VALUES (?, ?)"
);
$q->bind_param("ss", $user_names, $user_pass);
$q->execute();
$email=mysqli_real_escape_string($mysqli,"admin_email\\\' AND (SELECT CASE WHEN (SUBSTRING(admin_pass,1,1) = \\\'a\\\') THEN SLEEP(5) ELSE 1 END) AND \\\'1\\\' = \\\'1' AND admin_pass='pass\' --");
$pass=mysqli_real_escape_string($mysqli,"pass' --");
$r="select * from admins WHERE admin_email='".$email."' AND admin_pass='".$pass."'";
echo $r;