The program is basically right. However those dialogs are available only in the user interface to authenticated users and are not available on the live site - except the third one - but this is up to you whether you will allow the insert image/media dialog on your live site together with the
WYSIWYG editor (using UI personalization settings).
However, we are checking our code and query string parameters - have you tried to use some actual SQL injection? Sometimes it seems it is possible but in our code we are checking the inputs where it is possible to use SQL injection.
Moreover, I would like to recommend to always use latest version of Kentico
CMS + latest hotfix applied to it.
Best regards,
Juraj Ondrus