If you want to learn more about the nature of these attacks i suggest you look at the very first disclosure of the vulnerabilitiy. A nice example would be smashing the stack for fun and profit regarding to buffer overflows (
http://insecure.org/stf/smashstack.html) which gives great information about how the attack actually works. Now there are several sites and papers that outline these attacks for you. Almost all show you the how, but most are missing the why, which i think you are looking for.
after some googling i saw that even wikipedia has a nice writeup explaining SQL-injection. i guess the underground is not the only place any more to find such information.
Oh and remember that OWASP has alot of information also.