---
title: "What is SQL Injection?"  
description: "What is SQL Injection?"  
author: "Amit Singh"  
published: 2011-03-28  
updated: 2020-09-18  
canonical: https://www.mindstick.com/interview/607/what-is-sql-injection  
category: "db2"  
tags: ["db2"]  
reading_time: 2 minutes  

---

# What is SQL Injection?

The Test Data Inputs are \
1) ' (Single quote)\
2) '1'='1\
3) we can pass the same i/p's as query in the form of **SELECT * FROM users WHERE name = '' OR '1'='1';**\
(If the text field accepts that much characters)\
4) statement = "SELECT * FROM users WHERE name = '" + userName + "';"\
\
Before trying to pass those inputs as a security tester try to catch the Table Name and Attributes(fields) if so you can play with refined Data attributes and find out more Security issues by SQL Injection.\
\
First try to catch in the order Database Name->Table Name->Attributes->Data Types\

## Answers

### Answer by Amit Singh

The Test Data Inputs are \
1) ' (Single quote)\
2) '1'='1\
3) we can pass the same i/p's as query in the form of **SELECT * FROM users WHERE name = '' OR '1'='1';**\
(If the text field accepts that much characters)\
4) statement = "SELECT * FROM users WHERE name = '" + userName + "';"\
\
Before trying to pass those inputs as a security tester try to catch the Table Name and Attributes(fields) if so you can play with refined Data attributes and find out more Security issues by SQL Injection.\
\
First try to catch in the order Database Name->Table Name->Attributes->Data Types\


---

Original Source: https://www.mindstick.com/interview/607/what-is-sql-injection

Copyright © MindStick Software Pvt. Ltd. This Markdown version is provided for developers, AI systems, and offline reading.
