# SQL injection

> Smuggling database commands through input fields — the attack that turns 'name' into 'show me every user's password hash'.

When a query is built by concatenating strings, user input stops being data and becomes code: ' OR '1'='1 in a login field, a UNION SELECT in a search box. One of the oldest web vulnerabilities and still on every top-ten list because it keeps paying — full database read, sometimes write.

The fix is boring and total: parameterized queries, where the driver keeps data and code on separate channels. ORMs do it by default; the holes appear in the one hand-written query that 'just needed a dynamic table name'.

## Related terms

- https://dfieldsolutions.com/en/glossary/owasp-top-10.md
- https://dfieldsolutions.com/en/glossary/penetration-test.md
- https://dfieldsolutions.com/en/glossary/security-audit.md

---

Source: https://dfieldsolutions.com/en/glossary/sql-injection
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
