SQL Injection definition
SQL injection is a web security vulnerability that lets an attacker interfere with the database queries an application makes by inserting malicious SQL through user input. A successful attack can expose, modify or delete data, bypass logins and sometimes take control of the server. Parameterized queries are the primary defense against it.
How does SQL injection work?
SQL injection happens when an application builds a database query by concatenating user input directly into SQL text. Imagine a login check built as a string that inserts the username typed by the user. If an attacker enters a value containing a quote followed by OR '1'='1' and a comment marker, the query's logic changes so the condition is always true, and the database may return the first user, often an administrator, without a valid password.
The root cause is mixing code and data. The database cannot tell which part of the string was intended as SQL and which was user-supplied data, so attacker input becomes part of the command itself. Every injection variant, whatever its technique, exploits this same confusion between code and data.
Types of SQL injection
Attackers adapt their technique to how much the application reveals. Even when no data or errors are shown on screen, injection can still be exploited slowly by asking the database yes or no questions, so hiding error messages is not a defense on its own. The main variants are listed below.
- In-band: results or errors appear directly in the application's response.
- Union-based: UNION queries append data from other tables to normal results.
- Error-based: database error messages leak structure and data.
- Blind boolean-based: the attacker infers data from true or false page differences.
- Blind time-based: delays in responses reveal information.
- Out-of-band: data is sent to an external server the attacker controls.
How to prevent SQL injection
Use parameterized queries, also called prepared statements, everywhere. The SQL is sent with placeholders, and user values are passed separately, so they are always treated as data. Most ORMs, such as Django ORM, Hibernate, Entity Framework, Sequelize and Prisma, parameterize queries by default, but raw query features and string-built ORDER BY or table names can still be vulnerable and need allow-list validation.
Add defense in depth: validate input types and formats, give the application's database account only the permissions it needs, avoid displaying detailed database errors to users, and deploy a web application firewall to block common attack patterns. Static analysis tools and code review should flag any query built with string concatenation.
How to detect SQL injection
Penetration testers and tools such as Burp Suite and sqlmap probe inputs, headers, cookies and API parameters with crafted payloads and observe responses, errors and timing. Static application security testing tools find dangerous query construction in source code, and dynamic scanners such as ZAP test running applications for the injection risks covered by the OWASP Top 10. In production, database activity monitoring and web application firewall logs can reveal attempted attacks, and unusual query patterns should alert the security team.
Why SQL injection still matters
SQL injection is one of the oldest web vulnerabilities and remains part of the injection category in the OWASP Top 10, largely because legacy code, quick scripts and custom reporting features keep reintroducing it. One vulnerable endpoint can expose an entire database. Nexzem's security testing and code reviews check every data access path for injection, including APIs and admin tools that are often overlooked.