An injection flaw' is a

[v]ulnerability that is created from insecure coding techniques resulting in improper input validation, which allows attackers to relay malicious code through a web application to the underlying system.[1]

Overview Edit

"This class of vulnerabilities includes SQL injection, LDAP injection, and XPath injection."[2]

References Edit

  1. Payment Card Industry (PCI) Data Security Standard Glossary, Abbreviations and Acronyms (full-text).
  2. Id.

