SQL Injection: Code Review
Black-box testing finds bugs by poking from the outside. Code review finds them by reading the source — faster and more complete when you have the code. This exercise teaches the source-to-sink method on real-looking PHP: you will trace user input to the query that uses it, spot the exact unsafe line, and recognise safe code when you see it.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain the source-to-sink method of code review
- Identify sources (user input) and sinks (dangerous operations) in PHP
- Spot the line where unsanitised input reaches a SQL query
- Tell safe parameterised code from unsafe concatenated code at a glance
Before you start
These exercises cover what this one builds on.
- SQL Injection Medium
In this exercise
- Sources and sinks
- Read this login
- Name the vulnerable line
- Recognising the safe version
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points