some of the websec exploits are quite tricky/involved like blind sql injection (https://www.owasp.org/index.php/Blind_SQL_Injection). without tools like sql map you would need to write code in order to recover non-trivial amounts of data using blind sql injection.