What is SQL injection?¶
SQL injection supplies input that alters an application's database query. SQL-like text in a request can be a scan or failed attempt; successful injection requires an unintended database result.
Connect request to query execution¶
Preserve the exact request and parameter, authentication and session, application and database logs, generated queries where available, errors and response content. A normal HTTP status can contain an application error, while suppressed errors can hide successful processing.
Show how input reached a vulnerable query rather than assuming the payload's theoretical capability applied to the target.
Establish the database effect¶
Authentication bypass, data reading, alteration, deletion and function execution are different outcomes. Identify created sessions, changed records, exports or query results and the precise scope involved.
An injection may return one record, many records or only a true-or-false signal. Do not describe the whole database as exposed where only a narrow result is evidenced.
Key takeaway
Separate SQL injection payload, vulnerable query execution and actual database effect, reporting only the access or alteration scope demonstrated.