SQL injection
A flaw where user input is added directly to a database query, letting an attacker change the query to read or delete data.
- 01
Why it matters
SQL injection is one of the oldest known flaws but it still appears; if it succeeds, customer details, passwords and orders can leave in one go. It turns up especially in old hand-written code and in search or filter features added in a hurry. Parameterised queries close this risk at the root.
- 02
Example
Text typed into a shop's product search box is added straight into the query. By typing a crafted expression into the box, the attacker brings up the user table instead of the product list.
- 03
Common mistake
Thinking you are safe because input is cleaned by hand or quotes are stripped. The safe way is parameterised queries, where input is sent separately from the query, or a trusted database library.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.