Glossary Security

SQL injection

SQL injection is an attack in which input is crafted so that part of it is executed as database commands, letting an attacker read or change data.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

It arises when a program builds a query by pasting user input into a string, so an input such as ' OR '1'='1 changes the query's logic. The fix is parameterised queries (prepared statements), which keep data separate from the command. Escaping by hand is error-prone. Least-privilege database accounts limit the damage.

See also

  • Glossary Cross-site scripting (XSS)
    Cross-site scripting (XSS) is a vulnerability in which an attacker gets a website to deliver malicious script to other users' browsers.
  • Glossary Vulnerability
    A vulnerability is a weakness in software, hardware or a process that an attacker could exploit to do something unintended.
AdSense Placeholder
Slot: footer_leaderboard