SQL injection allows attackers to bypass authentication, manipulate data (insert, update, delete), and cause denial of service by executing intensive queries. Directory listing and traversal is a path-based vulnerability, not a direct outcome of SQL injection.