appsec.fyi

SQLi — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

SQLi: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 154 of 154 curated resources. Browse all 154 SQLi resources →

The Persistent Threat: Understanding SQL Injection

SQL Injection (SQLi) remains one of the most persistent and impactful web application vulnerabilities, despite its long history and well-understood mechanics [1][2][3][4]. Its persistence stems from a combination of factors: developer oversight, complex legacy codebases, and the sheer ubiquity of SQL databases across applications. For practitioners, a deep understanding of SQLi is not just about identifying simple bypasses; it's about recognizing its potential for profound data compromise and system control. This guide aims to provide an in-depth look at SQL injection from a practitioner's perspective, covering its core mechanics, advanced techniques, detection strategies, and robust prevention measures.

Core Mechanics: How SQLi Works

At its heart, SQL injection exploits the trust an application places in user-supplied input. When an application constructs SQL queries by directly concatenating user input without proper validation or sanitization, it creates an opening for malicious code to be injected. The database, which trusts the application, then executes these injected commands as if they were legitimate [1][5][6][3][4].

The fundamental vulnerability lies in the failure to distinguish between data and executable code. When user input intended as a data value is interpreted as part of the SQL command structure, attackers can manipulate the query's logic. This can range from simply altering a search query to bypass authentication, to extracting sensitive data, modifying records, or even executing operating system commands [1][7][3][4].

Input Validation and Sanitization Failures

The most common root cause of SQLi is insufficient input validation and sanitization [1][5][6][3][4]. Applications often fail to properly escape or sanitize special characters (like single quotes, double quotes, semicolons, and comments) that have specific meanings in SQL syntax. For example, a single quote can terminate a string literal, allowing an attacker to append their own SQL commands [8][9].

The Data vs. Code Distinction

SQL databases are designed to process commands. When an application mixes user-supplied data directly into SQL commands, the database cannot reliably differentiate between the intended query and the injected malicious code [1][3]. This lack of separation is the foundational weakness exploited by SQLi.

Notable Techniques and Attack Vectors

SQL injection is not a monolithic attack; it encompasses a diverse range of techniques, from simple bypasses to complex data exfiltration and privilege escalation chains. Understanding these variations is crucial for effective testing and defense.

In-Band SQL Injection

This is the most common type, where the attacker uses the same channel for both injecting the payload and receiving the results [4][10].

Inferential (Blind) SQL Injection

Blind SQLi is employed when an application does not directly display database errors or query results [1][21][22][23][4][8][17][10][24][25][19][26][27]. Attackers infer information by observing indirect effects:

Out-of-Band (OOB) SQL Injection

This technique is used when the application's response channel is unreliable or blocked for data exfiltration. Attackers trigger database functions that initiate an external network request (e.g., DNS lookup or HTTP request) to a server they control, sending data encoded within the request [22][8][17]. For example, using xp_dirtree in MSSQL or UTL_HTTP in Oracle can initiate external connections [32][8].

Second-Order SQL Injection

In this scenario, the malicious SQL payload is not executed immediately. Instead, it's stored in the database (e.g., in a user profile field, a log entry, or a comment) and executed later when that stored data is retrieved and used in another SQL query [33][2][30][34][35]. This delayed execution can bypass immediate input validation and WAFs. An example is storing a malicious string that, when later displayed or processed, triggers an injection [33][2][30][34][35].

Stacked Queries

This technique involves sending multiple SQL statements, separated by semicolons, in a single request. If the database backend and application permit stacked queries, an attacker can execute additional commands beyond the intended one, potentially performing DELETE, UPDATE, or even OS command execution if the database user has sufficient privileges [28][36][12][8][17][10][18]. For instance, terminating a read-only transaction with COMMIT; and then issuing a destructive command like DROP SCHEMA public CASCADE; can bypass restrictions [36].

Database-Specific Exploitation

Different database systems (MySQL, PostgreSQL, SQL Server, Oracle, SQLite, Snowflake) have unique functions and behaviors that can be exploited:

RCE via SQL Injection

SQL injection is not just about data theft; it can be a pathway to full Remote Code Execution (RCE). This is often achieved by:

JSON-Based SQL Injection

Modern applications often use JSON for data interchange. Attackers can embed SQL injection payloads within JSON structures, which may bypass WAFs that do not properly parse or inspect JSON content [58][59].

SQL Injection in Modern Frameworks and Technologies

SQLi is not confined to traditional web applications. It impacts newer technologies:

Detection and Prevention

Effective defense against SQL injection requires a multi-layered approach, encompassing secure coding practices, robust validation, and runtime protections.

Secure Coding Practices: The First Line of Defense

```python # Vulnerable (string concatenation) cursor.execute(f"SELECT * FROM users WHERE username = '{user_input}'")

# Secure (parameterized query) cursor.execute("SELECT * FROM users WHERE username = %s", (user_input,)) ```

Runtime Protections and Architectural Controls

Tooling for SQL Injection

A robust toolkit is essential for both finding and exploiting SQL injection vulnerabilities.

Recent Developments and Emerging Trends

SQL injection continues to evolve, adapting to new technologies and security measures.

Where to Go Deeper

For those seeking to deepen their expertise in SQL injection, numerous resources are available:

SQL injection is a fundamental vulnerability that demands continuous attention. By understanding its intricacies, mastering detection tools, and diligently applying secure coding practices, practitioners can significantly strengthen their defenses against this enduring threat.

Sources cited in this guide

  1. SQL injection remains a persistent cyber threat after two decades — informante.web.na
  2. Exploiting Second-Order SQL Injection to Retrieve the Flag — medium.com
  3. SQL Injection - OWASP — owasp.org
  4. 7 Types of SQL Injection Attacks & How to Prevent Them — sentinelone.com
  5. Getting started with query parameterization — snyk.io
  6. Preventing SQL injection attacks in Node.js — snyk.io
  7. Oracle SQL Injection Attack Enables Remote Code Execution — esecurityplanet.com
  8. SQL Injection for Bug Bounty Hunters | YesWeHack — yeswehack.com
  9. SQL Injection 101: Common Defense Methods Hackers Should Be Aware Of — null-byte.wonderhowto.com
  10. SQL Injection Cheatsheet 2021 — hackersonlineclub.com
  11. From Bug to Schema: Exploring Error-Based SQL Injection on an Authenticating Portal — infosecwriteups.com
  12. SQL Injection Cheat Sheet - Invicti — invicti.com
  13. SQLi Payloads - Classic, Blind, Error-Based, Time-Based, WAF Bypass — github.com
  14. Exploiting Error Based SQL Injections & Bypassing Restrictions — link.medium.com
  15. Snowflake SQL Injection via Compile-Time Constant Folding with SYSTEM$WAIT — infosecwriteups.com
  16. Pentesting PostgreSQL with SQL Injections — onsecurity.io
  17. PayloadsAllTheThings - SQL Injection — github.com
  18. SQL Injection Cheat Sheet by Netsparker — netsparker.com
  19. https://medium.com/bugbountywriteup/sql-injection-time-and-boolean-based-27239b6a55e8?source=twitterShare-1764222123d3-1576594710&_referrer=twitter&_branch_match_id=732557985002302401 — medium.com
  20. SQL injection to RCE — medium.com
  21. Discovering an Time-Based Blind SQL Injection in a Tamil Nadu Government Web Portal (TANGEDCO) — infosecwriteups.com
  22. When the Database Won't Talk: A Deep Dive into Blind SQLi — hadrian.io
  23. Bug Bounty Bootcamp #29: Boolean Blind SQL Injection Part 2 — infosecwriteups.com
  24. https://medium.com/bugbountywriteup/sql-injection-time-and-boolean-based-27239b6a55e8?source=twitterShare-1764222123d3-1576594710&_referrer=twitter&_branch_match_id=732557985002302401 — medium.com
  25. DVWA 1.9+: Blind SQL Injection with SQLMap — link.medium.com
  26. Making a Blind SQL Injection a Little Less Blind — medium.com
  27. BSQLinjector – Blind SQL Injection Tool Download in Ruby — darknet.org.uk
  28. SQL Injection and Postgres: An Adventure to Eventual RCE — pulsesecurity.co.nz
  29. Exploiting Time-Based SQL Injections: Data Exfiltration — medium.com
  30. Advanced SQL Injection Techniques in Modern Web Apps — gauravsingh-cybersecurity.github.io
  31. GitHub - danialhalo/SqliSniper: Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers — github.com
  32. Second-Order SQL Injection with Stored Procedures and DNS-Based Egress — netspi.com
  33. Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability — securityweek.com
  34. Exploiting second order blind SQL injection — link.medium.com
  35. Demystifying SQL Injection: A Comprehensive Guide to Understanding SQL Injection Risks — akto.io
  36. MCP Vulnerability Case Study: SQL Injection in the Postgres MCP Server — securitylabs.datadoghq.com
  37. Attackers hid malware inside Oracle Database after SQL injection breach — csoonline.com
  38. Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access — thehackernews.com
  39. Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw — itsecurityguru.org
  40. CVE-2025-52694 PoC: Critical SQL Injection in Advantech IoTSuite/SaaS-Composer — github.com
  41. CVE-2025-1094 WebSocket and SQL Injection Exploit Script — github.com
  42. Breaking the Superuser Guardrails of managed-PostgreSQL Providers — mehmetince.net
  43. Rapid7 Analysis: CVE-2024-12356 — rapid7.com
  44. CVE-2025-1094: PostgreSQL SQL Injection Vulnerability — armosec.io
  45. CVE-2025-1094: PostgreSQL psql SQL Injection (Fixed) — Rapid7 — rapid7.com
  46. PostgreSQL CVE-2025-1094: Quoting APIs SQL Injection — postgresql.org
  47. SQL Injection 2025 Advanced Exploitation & Defense Guide — broadchannel.org
  48. Vulnerability analysis, Security Papers, Exploit Tutorials - Part 12975 — exploit-db.com
  49. Advanced SQL Injection Cheatsheet — github.com
  50. SQL Attack (Constraint-based) - Dhaval Kapil — dhavalkapil.com
  51. https://portswigger.net/web-security/sql-injection/cheat-sheet — portswigger.net
  52. Hackers run khunt post-exploitation toolkit from Oracle database — bleepingcomputer.com
  53. How to turn SQL injection into an RCE or a file read? Case study of 128 bug bounty reports — youtube.com
  54. From SQLi to RCE - Exploiting LangGraphs Checkpointer — research.checkpoint.com
  55. From SQL Injection to Infrastructure-Level RCE: A PostgreSQL Superuser Compromise — infosecwriteups.com
  56. Hackers Exploit Newly Patched WordPress Vulnerabilities — techrepublic.com
  57. Unauthenticated RCE in WordPress core (wp2shell) — aikido.dev
  58. WAF Bypass Using JSON-Based SQL Injection Attacks — picussecurity.com
  59. open-appsec ML-based WAF protects against modern SQLi AutoSpear evasion techniques — openappsec.io
  60. Identifying SQL Injections in a GraphQL API — praetorian.com
  61. SQL Injection in GraphQL — 0xgad.medium.com
  62. U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog — securityaffairs.com
  63. CVE-2026-42208: Critical Pre-Auth SQL Injection in LiteLLM Actively Exploited Within 36 Hours of Disclosure — rescana.com
  64. CVE-2026-42208: LiteLLM SQL Injection Leaks Upstream API Keys — abhs.in
  65. CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure — securityaffairs.com
  66. Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure — securityweek.com
  67. LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure — thehackernews.com
  68. Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw — bleepingcomputer.com
  69. SQL injection isn't dead — aikido.dev
  70. Preventing SQL injection in C# with Entity Framework — snyk.io
  71. What is SQL Injection? How to Prevent SQL Injection | Fortinet — fortinet.com
  72. Vulnerabilities in Redeight CMS software — cert.pl
  73. SQL Attack (Constraint-based) - Dhaval Kapil — dhavalkapil.com
  74. WAF Bypass Techniques for SQL Injection — nav1n0x.gitbook.io
  75. WAF Testing Guide: How to Validate Web Application Firewalls — picussecurity.com
  76. Bypassing WAFs in 2025: New Techniques and Evasion Tactics — medium.com
  77. Exploiting an SQL Injection with WAF Bypass — vaadata.com
  78. SQL Injection Bypassing WAF | OWASP — owasp.org
  79. SQLMap Tamper Collection: Modern WAF Bypass Scripts (Cloudflare, AWS, Azure) — github.com
  80. BWAFSQLi: Bypassing Web Application Firewall with Adversarial SQL Injections — dl.acm.org
  81. Advanced Boolean-Based SQLi Filter Bypass Techniques — secjuice.com
  82. Bypassing WAF with Adversarial SQL — dl.acm.org
  83. ServiceNow Patches 3 Critical Code Injection Vulnerabilities — securityweek.com
  84. SQL Injection in Password Reset: Full Database, One Email — infosecwriteups.com
  85. CVE-2026-26116: SQL Server SQL Injection — sentinelone.com
  86. CVE-2026-27697: Basercms SQLi Vulnerability — sentinelone.com
  87. CVE-2026-5197: Student Membership System SQLi Vulnerability — sentinelone.com
  88. SQL injection isn't dead — aikido.dev
  89. SQLMap Cheat Sheet: Commands, Options, and Advanced Features — stationx.net
  90. NucleiFuzzer - Powerful Automation Tool For Detecting XSS, SQLi, SSRF, Open — kitploit.com
  91. https://vavkamil.cz/2019/10/09/understanding-the-full-potential-of-sqlmap-during-bug-bounty-hunting/ — vavkamil.cz
  92. 9 SQLi Detection Tools You Need to Know in 2023 — analyticsinsight.net
  93. TryHackMe | SQHell — tryhackme.com
  94. How I Found Multiple SQL Injections in 5 Minutes in Bug Bounty — medium.com
  95. How I Found multiple SQL Injection with FFUF and Sqlmap in a few minutes — 0xmahmoudjo0.medium.com
  96. https://secnhack.in/website-penetration-testing-and-database-hacking-with-sqlmap/ — secnhack.in
  97. Identifying & Exploiting SQL Injection: Manual & Automated — link.medium.com
  98. Understanding the full potential of sqlmap during bug bounty hunting — vavkamil.cz
  99. http://www.darknet.org.uk/2017/09/bsqlinjector-blind-sql-injection-tool-download-ruby/ — darknet.org.uk
  100. Comprehensive Guide to Sqlmap (Target Options) — linkedin.com
  101. Vibe-Coding's Hidden Danger: SQL Injection Risks Go Live — techbuzz.ai
  102. Writeups for Damn Vulnerable Web Application (DVWA) — medium.com
  103. https://github.com/yeswehack/vulnerable-code-snippets — github.com
  104. SQL Injection Wiki — sqlwiki.netspi.com
  105. SQL Injection Wiki — sqlwiki.netspi.com
  106. CVE Search: SQL Injection — cve.org
  107. From SQL Injection to Remote Code Execution: Following an Unexpected Attack Chain — infosecwriteups.com
  108. Early exploitation attempts observed of GeoServer zero day — fieldeffect.com
  109. Trezor Data Breach Analysis: 14000 Customers Exposed in ShipMonk Metabase SQL Injection Incident — rescana.com
  110. Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898 — bishopfox.com
  111. Inside the Metabase SQLi: Exploited in the Wild — wiz.io
  112. Inside the Metabase SQLi: Exploited in the Wild — wiz.io
  113. Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — thehackernews.com
  114. Vulnerabilities in Windu CMS software — cert.pl
  115. Unauthenticated RCE in WordPress core (wp2shell), via SQL injection — aikido.dev
  116. The Security Bug That Almost Shipped — hackernoon.com
  117. Anatomy of a Critical SQL Injection: Lessons From CVE-2020-24932 — hackernoon.com
  118. Making A SQLi Lab Is Not Difficult, Build One With Me. — infosecwriteups.com
  119. Ghost CMS Vulnerability Exploited to Hack Over 700 Websites — securityweek.com
  120. Ghost CMS CVE-2026-26980 Exploited to Hijack 700 Sites for ClickFix Attacks — thehackernews.com
  121. Avada Builder Flaws Expose One Million WordPress Sites — infosecurity-magazine.com
  122. Bug hunter tracks down three serious MCP database flaws one left unpatched — theregister.com
  123. 38 Vulnerabilities Found in OpenEMR Medical Software — securityweek.com
  124. NoSQL Injection: Advanced Exploitation Guide — intigriti.com
  125. Exploits Explained: NoSQL Injection Returns Private Information — synack.com
  126. Unauthenticated SQL Injection in GUI — Fortinet PSIRT — fortiguard.fortinet.com
  127. CVE-2025-26794: Blind SQL Injection in Exim 4.98 — Writeup — github.com
  128. April 2026 Patch Tuesday: Critical Vulnerabilities in SAP Adobe Microsoft SharePoint Fortinet and ColdFusion Threaten Enterprise Security — rescana.com
  129. Exploiting SQL Injection Vulnerability - Bug Bounty Writeup — medium.com
  130. SAP Security Patch Day April 2026: Critical Vulnerabilities CVSS 9.9 SQL Injection and Authorization Risks — erp.today
  131. 400K WordPress Sites Exposed by Elementor Ally Plugin SQL Flaw — esecurityplanet.com
  132. SQL Injection in 2026: It Took One Apostrophe — udayshelke17-40981.medium.com
  133. SQL Injection Security Vulnerabilities — cvedetails.com
  134. SQL Injection Tutorial & Examples - PortSwigger — portswigger.net
  135. SQL Injection (SQLi) Guide - SecPortal — secportal.io
  136. New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries — thehackernews.com
  137. https://weekly.infosecwriteups.com/iw-weekly-39-10-000-bounty-zero-click-account-takeover-stored-xss-open-redirection-vulnerability-sql-injection-rce-reconnaissance-techniques-and-much-more/ — weekly.infosecwriteups.com
  138. SQL Injection Cheat Sheet by Netsparker — netsparker.com
  139. SQLMap Command Generator — acorzo1983.github.io
  140. BChecks/vulnerability-classes/injection at main · PortSwigger/BChecks · GitHub — github.com
  141. Test website for SQL injection vulnerabilities using Python — imran-niaz.medium.com
  142. Tag Archives: SQL Injection — kscottmorrison.com
  143. [ODATA-1110] Provide guidance for sql-injection type attacks — issues.oasis-open.org
  144. Favorite tweet by @harshbothra_ — twitter.com
  145. Web Attack Cheat Sheet — github.com
  146. 10 Types of Web Vulnerabilities that are Often Missed — labs.detectify.com
  147. SQL Injection 101: Common Defense Methods Hackers Should Be Aware Of — null-byte.wonderhowto.com
  148. Barebones Application Security — SQL Injection (SQLi) — medium.com
  149. Vulnerability analysis, Security Papers, Exploit Tutorials - Part 12975 — exploit-db.com
📚 This guide is synthesized from the full text of resources curated in the SQLi library, and refreshed as new material is added.