Por ahora, esta lección está en inglés.
When input becomes code
SQL injection happens when user text is pasted into a query and the database runs part of it as SQL. Injection has appeared in every edition of the OWASP Top 10, and the fix is a habit you can learn in minutes.