SQLi
SQL Injection
SQL Injection is a vulnerability where an attacker inserts malicious SQL statements into input fields to manipulate a database. Successful SQLi can expose, modify, or delete data and sometimes lead to full server compromise.
Cómo se usa en ciberseguridad
Penetration testers test login forms, search fields, and API parameters for SQLi using manual techniques and tools like sqlmap. Security engineers prevent SQLi by enforcing parameterized queries and input validation across all database interactions. DAST scanners flag SQLi findings for triage by application security teams.
Término relacionado en el glosario: sql injection
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.