First, I tried figuring out if the site was vulnerable to SQL injection by adding a single quote at the end of the get parameters and this what i got
Source E