I think that you must use Query in rest because here you have where (you can do a simple 1=1). In find the function esri compare with equal (and manage contain) and for issue with sql injection I don't think that you can set subquery or find: ('Test' or 1=1)