SQLi Vulnerable Application

Welcome to the Security Awareness Month SQLi Challenge!


This application is intentionally vulnerable to SQL Injection (SQLi) as part of our Security Awareness Month activities. Your goal is to find the hidden flag in the format 'this_is_an_example'.

This application's database is recreated every time the server starts.

Register Login

What is SQL Injection (SQLi)?

SQL Injection (SQLi) is a type of security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. This is typically done by inserting malicious SQL code into a query via user input fields.

Why is SQLi Dangerous?

SQLi is one of the most dangerous vulnerabilities because it can allow attackers to:

  • Bypass authentication mechanisms and access sensitive data.
  • Alter, delete, or corrupt database data.
  • Execute administrative operations on the database.
  • Potentially execute commands on the underlying operating system.

How to Prevent SQLi?

  • Use Parameterized Queries
  • Use ORM Libraries
  • Input Validation and Sanitization
  • Least Privilege Principle

References