SQL injection
SQL injection is what happens when text typed into a form changes the meaning of a database query rather than just its contents.
It has been well understood for over twenty years, the fix is straightforward, and it keeps appearing, because the insecure way of building a query is the obvious way and the secure way has to be learned. The consequences run from reading the entire customer database to changing it. It remains one of the most reliable ways into an application that nobody has looked at properly.
Checked against the primary source.
