SQL injection (SQLi) is a web application vulnerability that allows attackers to interfere with database queries by inserting malicious SQL code into input fields. If the application does not sanitize user input, attackers can access, modify, or delete data, bypass authentication, or execute system commands. SQL injection is one of the most common web vulnerabilities and appears in the OWASP Top 10. Prevention requires parameterized queries, prepared statements, input validation, and least-privilege database permissions.
Cybersecurity
SQL Injection
More Cybersecurity Terms
Related Articles
Cybersecurity
SQL Injection Tutorial: Learn, Practice & Defend with Free Labs
Understand SQL injection attacks from the ground up. Learn how attackers exploit databases, practice in safe environments, and defend your applications.
CybersecurityHow to Hack a Web Application: Security Testing Tutorial for Beginners
Learn web application security testing from scratch. Practice SQL injection, XSS, CSRF, and other vulnerabilities with free hands-on labs.