security/sql-injection-how-a-stray-quote-mark-turns-data-into-instructions.md

SQL injection: how a stray quote mark turns data into instructions

Security · 4 min read ·

A search box looks harmless, but if a program builds its database question by gluing text together, a stray quote mark can turn a visitor's words into instructions. That bug is called SQL injection.

Type your own input into a live playground and watch where the data ends and the instructions begin, then see the one-line fix, placeholders, working in real Python output.

Code snippet WHERE name = 'x' OR '1'='1' with the quoted data in orange and the OR instruction in red

$ ls security/

see all →