A Classification of SQL-Injection Attacks and Countermeasures¶
Halfond, W. G. J., Viegas, Jeremy, Orso, & Alessandro. (2006). A Classification of SQL-Injection Attacks and Countermeasures. Proceedings of the International Symposium on Secure Software Engineering.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Prepared Statement
- If a value is pulled from a trusted-looking place — a column populated earlier from user input — and then concatenated into a new statement, that is second-order SQL injection, and the prepared statement upstream did nothing to stop it because the danger was introduced downstream.
This sourceDefines second-order SQL injection as stored input later reused in a newly constructed query, which remains unsafe when only the earlier write was parameterized.
- If a value is pulled from a trusted-looking place — a column populated earlier from user input — and then concatenated into a new statement, that is second-order SQL injection, and the prepared statement upstream did nothing to stop it because the danger was introduced downstream.
Verification¶
Does it exist? Not checked yet. This entry carries no identifier to resolve. It was extracted from the citation as written in the article, normalized, and deduplicated against the rest of the registry.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:0625e4972ff7 · see in the full table