Log entry 3 contains the command nullif (1337,1337). This is a SQL command that evaluates to 0 if the two arguments are equal and null if they are not equal. The attacker is trying to exploit the command injection vulnerability by injecting this command into the application.