SQL Injection: Code Review

🔒 Pro Medium Code review Online Avg. time 30 min Solved by 0 2 keys · 50 pts Code Review

Black-box testing finds bugs by poking from the outside. Code review finds them by reading the source — faster and more complete when you have the code. This exercise teaches the source-to-sink method on real-looking PHP: you will trace user input to the query that uses it, spot the exact unsafe line, and recognise safe code when you see it.

Skills covered: Code ReviewSQL Injection
Log in or create a free account to submit keys and track your progress.

What you will learn

  • Explain the source-to-sink method of code review
  • Identify sources (user input) and sinks (dangerous operations) in PHP
  • Spot the line where unsanitised input reaches a SQL query
  • Tell safe parameterised code from unsafe concatenated code at a glance

Before you start

These exercises cover what this one builds on.

In this exercise

  1. Sources and sinks
  2. Read this login
  3. Name the vulnerable line
  4. Recognising the safe version
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

4 sections · 2 keys · 50 points