SQL injection
Description
Dynamic SQL statements are generated without using parameterized statements or stored procedures.
Impact
Obtain information from the database by injecting SQL statements.
Recommendation
- Perform database queries through parameterized statements or stored procedures. - Never assume input is safe. Always treat data sources as untrusted and assume any input may be an injection attempt.
Threat
Authenticated attacker from the Internet.
Expected Remediation Time
⏱️ 30 minutes.
Rules
Java Like Clause Unescaped InputC Sharp String Format Sql InjectionPhp Sql Injection Concat QueryPhp Mysql Query Unsanitized Table NamePython Sql Injection Unstrusted DataDart Raw Sql InjectionTypescript Nest Mysql InjectionRust Diesel Sqlx Sql InjectionTypescript Nest Sqlite InjectionSwift Tainted Sql InjectionTypescript Sql Injection Untrusted InputGo Gorm Sql InjectionJavascript Sql Injection Untrusted InputTypescript Nest Typeorm Sql InjectionElixir Mysql Sql InjectionDart Insecure Storage Sql InjectionRuby Sql Injection User InputTypescript Nest Sequelize Sql InjectionScala Unsafe Xquery InjectionScala Tainted Sql InjectionC Sharp Unsanitized Input In SqlJava Api Sql InjectionTypescript Raw Query With User InputElixir Ecto Sql InjectionElixir Postgresql Sql InjectionGo Query String Sql InjectionPython Rawsql With Unvalidated InputPhp Raw Sql InjectionTypescript Nest Pg Sql InjectionJava Callable Statement Sql InjectionKotlin Raw Sql InjectionPython Drivers Sql InjectionTypescript Nest Mssql InjectionTypescript Nest Oracle Sql InjectionC Sharp Raw Sql With User Input