And I am using that tool, it is very effective and all you have to do is
Just select the form where you need to check for SQL injection and in the browser Tools -> sqlinject me -> open SQL inject me Slide bar.
You will find the add on coming in the left side , just click on the Test all forms with all attacks , which is a generally check all the form with the possible string attacks and the result will open up in a separate tab where you can analyze the result for which sql string it failed.
Rest i guess you will explore your self the tool is very kool to check the SQL injection in the web page.
BEWARE Don run it in Live server it will submit the form each and every time the data will get stored in DB, Check your database once you complete a test, DON'T Run in live server b'cos u may not have the client server details, Best to do it in a TEST Server and Check ur DB often.
I was used that tool, its really great and Result (SQL injection and XSS) also very clear. One more thing, I got the result but i want to know how to verify this result is correct one?Why i asked this questions is developers doesn't accept the result for SQL injection and XSS.
I would like to know how to fix those issue by developers. Could you please give some Tips and Suggestion?