Skip to content · ⁨Passer au contenu⁩

SQL injection · ⁨injection SQL⁩

English

When input becomes a command

  • Many apps build a database query by gluing the user's input into a string. That is dangerous.
  • If an attacker types SQL as their input, it can become part of the query. This is SQL injection — the most famous web attack.

Français

Quand l'entrée devient une commande

  • De nombreuses applications construisent une requête de base de données en collant l'entrée utilisateur dans une chaîne. C'est dangereux.
  • Si un attaquant tape SQL comme entrée, cela peut faire partie de la requête. C'est l'injection SQL — l'attaque web la plus célèbre.

Entrée malveillante OR 1=1 rend la clause WHERE toujours vraie, fuyant toutes les lignes

Log in or create account · ⁨Se connecter ou créer un compte⁩

IGCSE, A-Level & AP