What Is SQL Injection?
How untrusted input becomes a database command, and how to stop it.
What Is SQL Injection?
SQL injection happens when user input is concatenated directly into a database query instead of being treated as pure data. If an application builds a query like SELECT * FROM users WHERE name = ' + input + ', an attacker can supply input that changes the query's meaning entirely.
Why it still happens
Despite being decades old, SQLi persists because string-concatenated queries are the "obvious" way to write one, especially in legacy code.
Detection
Web application firewalls can catch common patterns, but the more reliable signal is application-layer logging: unexpected quote characters, UNION, or -- sequences in fields that should just be names or emails.
Prevention
Parameterized queries (prepared statements) are the fix: the database treats input strictly as data, never as part of the query structure, regardless of what characters it contains.