Injection attacks exploit insufficient input validation to insert malicious code into application queries or commands, enabling unauthorized data access and system compromise.
An injection attack occurs when an attacker inserts malicious code or commands into application inputs that are processed by an interpreter without proper validation or sanitization. Common types include SQL injection, command injection, LDAP injection, and XPath injection. Injection consistently ranks among the most critical web application vulnerabilities due to its prevalence and potential for severe impact.
SQL injection exploits applications that construct database queries by concatenating user input without parameterization. Attackers insert SQL syntax into input fields to modify query logic, extract data, bypass authentication, or execute administrative operations. A simple example manipulates a login query to return all records, granting unauthorized access without valid credentials.
Additional types include OS command injection that executes system commands, LDAP injection targeting directory services, NoSQL injection exploiting document databases, XML injection and XXE attacks, Server-Side Template Injection exploiting template engines, and expression language injection targeting framework interpreters. Each targets a different backend technology but exploits the same fundamental input handling weakness.
Testers systematically submit crafted payloads through all application input vectors including form fields, URL parameters, HTTP headers, cookies, and API endpoints. They observe application responses for error messages, timing differences, and behavioral changes indicating interpreter interaction. Automated tools like SQLMap handle common injection patterns while manual testing discovers complex second-order and blind injection flaws.
Blind injection occurs when the application does not return visible error messages or query results to the attacker. Boolean-based blind injection infers data through true/false response differences. Time-based blind injection uses deliberate delays to extract information one bit at a time. Blind injection is harder to exploit but equally dangerous because attackers can still extract entire databases given sufficient time.
Primary prevention uses parameterized queries or prepared statements that separate code from data. Input validation rejects unexpected characters and formats. Output encoding prevents injected content from being interpreted. Web application firewalls provide an additional detection layer. Least-privilege database accounts limit the impact of successful injection by restricting available operations and data access.
Second-order injection occurs when malicious input is stored safely but later retrieved and used unsafely in a different query or command. The initial input passes validation and storage securely, but a separate application function processes the stored data without sanitization. This attack is difficult to detect because the injection point and execution point are in different application components.
Successful injection attacks can expose entire databases containing customer data, financial records, and credentials. Attackers may modify or delete data, escalate privileges to administrator level, execute operating system commands for full server compromise, and pivot to internal networks. Business impacts include regulatory fines, litigation costs, reputational damage, and operational disruption from data integrity violations.