Detecting and Mitigating SQL Injection Vulnerabilities in Web Applications

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Neupane, Sagar
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911016122580992
author Neupane, Sagar
author_facet Neupane, Sagar
contents SQL injection (SQLi) remains a critical vulnerability in web applications, enabling attackers to manipulate databases through malicious inputs. Despite advancements in mitigation techniques, the evolving complexity of web applications and attack strategies continues to pose significant risks. This paper presents a comprehensive penetration testing methodology to identify, exploit, and mitigate SQLi vulnerabilities in a PHP-MySQL-based web application. Utilizing tools such as OWASP ZAP, sqlmap, and Nmap, the study demonstrates a systematic approach to vulnerability assessment and remediation. The findings underscore the efficacy of input sanitization and prepared statements in mitigating SQLi risks, while highlighting the need for ongoing security assessments to address emerging threats. The study contributes to the field by providing practical insights into effective detection and prevention strategies, supported by a real-world case study.
format Preprint
id arxiv_https___arxiv_org_abs_2506_17245
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Detecting and Mitigating SQL Injection Vulnerabilities in Web Applications
Neupane, Sagar
Cryptography and Security
68M25 (Primary), 68Q85, 94A60 (Secondary)
D.4.6; K.6.5; H.2.0; H.3.3
SQL injection (SQLi) remains a critical vulnerability in web applications, enabling attackers to manipulate databases through malicious inputs. Despite advancements in mitigation techniques, the evolving complexity of web applications and attack strategies continues to pose significant risks. This paper presents a comprehensive penetration testing methodology to identify, exploit, and mitigate SQLi vulnerabilities in a PHP-MySQL-based web application. Utilizing tools such as OWASP ZAP, sqlmap, and Nmap, the study demonstrates a systematic approach to vulnerability assessment and remediation. The findings underscore the efficacy of input sanitization and prepared statements in mitigating SQLi risks, while highlighting the need for ongoing security assessments to address emerging threats. The study contributes to the field by providing practical insights into effective detection and prevention strategies, supported by a real-world case study.
title Detecting and Mitigating SQL Injection Vulnerabilities in Web Applications
topic Cryptography and Security
68M25 (Primary), 68Q85, 94A60 (Secondary)
D.4.6; K.6.5; H.2.0; H.3.3
url https://arxiv.org/abs/2506.17245