The primary effect of a successful SQL injection attack is unauthorized access to the application's database, allowing the attacker to view, edit, or delete sensitive data. It does not typically grant direct control over the entire operating system or local files of the server.