What type of cyberattack inserts malicious database commands through a website input field?

The story behind the answer

SQL injection is a cyberattack that inserts malicious database commands through a website input field.

The attack occurs when an application combines untrusted user input with an SQL query without safely separating data from code. An attacker may then alter the query’s meaning, potentially reading, changing or deleting database records, depending on the application’s permissions and defenses.

SQL injection became a foundational example of insecure input handling in web security. It can affect login forms, search boxes, URL parameters and other places where an application accepts data. The vulnerability is not caused by SQL itself; it results from unsafe construction or processing of database queries.

Common defenses include parameterized queries, prepared statements, careful input handling and restricting database privileges. The term is sometimes confused with cross-site scripting, but SQL injection targets database queries, while cross-site scripting targets the execution of scripts in a user’s browser.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: