SQL Injection Attacks in Web Application
Zhou Guo-xiang · Information Security and Communications Privacy · 2010
SQL injection is a technique for exploiting the Web application that use client-supplied data for SQL queries and, without stripping potentially harmful characters, execute SQL queries in back-end database, thus producing an attack different from the expectation. In the Internet or intranet, remarkable numbers of SQL injections exist the Web application, which is easily exploited by attackers. However, proper countermeasures adopted in Web application could prevent SQL injections or reduce the loss resulted from the attacks.