SQL injection

Input that escapes a string value and becomes part of a database query, letting an attacker read, change or bypass what the query was meant to do.

Learn it hands-on