International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 185 - Number 38 |
Year of Publication: 2023 |
Authors: S M Sarwar Mahmud, Taofica Amrine, Muhammad Anwarul Azim |
10.5120/ijca2023923192 |
S M Sarwar Mahmud, Taofica Amrine, Muhammad Anwarul Azim . SQL Injection Attack Vulnerabilities of Web Application and Detection. International Journal of Computer Applications. 185, 38 ( Nov 2023), 41-48. DOI=10.5120/ijca2023923192
SQL injection in database-driven web applications is a severe security risk. Using this injection attack, someone can steal potentially sensitive information and access the application's underlying database. Confidential data can be destroyed, lost, or stolen, websites can be vandalized, and unauthorized access to systems or accounts from a successful SQL injection attack. Individual devices or large networks can be compromised. The objective is to make a dataset or payloads of SQL injection vulnerability with web applications and perform an analysis to make a good prediction of the vulnerability. To provide a practical approach for vulnerability assessment and penetration testers which helps to ensure accurate results. This paper discussed the new method for detecting SQL injection using the proposed payloads and developed a Web Application Firewall that will reduce SQL Injection Attacks. With the help of These proposed payloads, the Web Application Firewall greatly improved and reduced any SQL injection attacks effectively.