what is sql injection?
Answers were Sorted based on User's Feedback
Answer / reva ram sahu
SQL Injection happens when a developer accepts user input
that is directly placed into a SQL Statement and doesn't
properly filter out dangerous characters. This can allow an
attacker to not only steal data from your database, but also
modify and delete it. Certain SQL Servers such as Microsoft
SQL Server contain Stored and Extended Procedures (database
server functions). If an attacker can obtain access to these
Procedures it may be possible to compromise the entire
machine. Attackers commonly insert single qoutes into a
URL's query string, or into a forms input field to test for
SQL Injection. If an attacker receives an error message like
the one below there is a good chance that the application is
vulnerable to SQL Injection.
Is This Answer Correct ? | 6 Yes | 1 No |
Answer / a
It's a secuity vulnerability that occurs between the
database layer of an application.
Is This Answer Correct ? | 5 Yes | 1 No |
What is the difference between clustered index and primary key?
How to see existing views in ms sql server?
Is it possible to create tables in stored procedures using a variable for the table name?
What is the difference between constraints and triggers?
can any one please send sql quries most used in applications.
what is the difference between group and having give an example with query and sample output
Can sql servers link to other servers?
What is the difference between push and pull subscription? : sql server replication
How do you optimize Sql queries ?
What are the fixed server level roles? : sql server security
How to convert numeric values to integers in ms sql server?
If there is failure during updation of certain rows, what will be the state?