| Details | |
|---|---|
| Alert ID | 200000-3 |
| Alert Type | Tool |
| Status | alpha |
| Risk | High |
| CWE | 89 |
| WASC | |
| Technologies Targeted | All |
| Tags |
CWE-89 OWASP_2021_A03 OWASP_2025_A05 TOOL_PTK |
Summary
A SQL injection attack consists of insertion or injection of a SQL query via the input data from the client to the application. A successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. SQL injection attacks are a type of injection attack, in which SQL commands are injected into data-plane input in order to affect the execution of predefined SQL commands.
Generated by OWASP PTK DAST Module