5
I don't know, from which file he got the password, but it's fact, that he got it. And yes, he can change everything now in my site. Because he is my friend, he didn't hacked my site totaly, he just changed a few things here (wanted to show, that it's really simple to hack this CMS and he know all the passwords). I am able to login to my web as admin and fix all him changes, because he isn't a "black hat" and he didn't take ownership of my website.
P.S. he said, that it's needed just to "make SQL injection" for hacking everything.