When a query is built by concatenating strings, user input stops being data and becomes code: ' OR '1'='1 in a login field, a UNION SELECT in a search box. One of the oldest web vulnerabilities and still on every top-ten list because it keeps paying — full database read, sometimes write.
The fix is boring and total: parameterized queries, where the driver keeps data and code on separate channels. ORMs do it by default; the holes appear in the one hand-written query that 'just needed a dynamic table name'.
Related terms
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
Penetration test
An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
