en.wikipedia.org/wiki/SQL_injection
4 corrections found
In 2017, the OWASP Top 10 Application Security Risks grouped SQL injection under the broader category of "Injection," ranking it as the third most critical security threat.
OWASP did group SQL injection under the broader “Injection” category in 2017, but that category was ranked #1 in the 2017 Top 10, not #3.
Full reasoning
The ranking in this sentence is incorrect. OWASP’s official 2017 Top 10 page labels the category “A1:2017-Injection”, which means Injection was ranked first in the 2017 list, not third. OWASP’s 2021 Top 10 later moved Injection to A03:2021, so the article appears to have mixed the 2017 and 2021 rankings.
Because the sentence explicitly says 2017 and then says Injection was ranked third, it contradicts OWASP’s published 2017 classification.
2 sources
- OWASP Top Ten 2017 | A1:2017-Injection | OWASP Foundation
The official OWASP 2017 page is titled "A1:2017-Injection," showing that Injection was the #1 category in the 2017 Top 10.
- A03 Injection - OWASP Top 10:2021
OWASP’s 2021 page says "Injection slides down to the third position," indicating that third place applies to 2021, not 2017.
By 2021, injection remained a widespread issue, detected in 94% of analyzed applications, with reported incidence rates reaching up to 19%.
OWASP did not say injection was found in 94% of applications. It said 94% of applications were tested for some form of injection; the page separately lists average coverage as 47.90%.
Full reasoning
This sentence misstates OWASP’s 2021 metric. The official OWASP 2021 Injection page says “94% of the applications were tested for some form of injection” and lists Max Coverage 94.04% and Avg Coverage 47.90%. That is not the same as saying injection was detected in 94% of analyzed applications.
In other words, the 94% figure refers to testing coverage, not confirmed prevalence of injection flaws across applications. OWASP’s page also separately reports a max incidence rate of 19.09% and average incidence rate of 3.37%, which further shows that the article has conflated distinct OWASP statistics.
1 source
- A03 Injection - OWASP Top 10:2021
OWASP states: "94% of the applications were tested for some form of injection" and lists "Max Coverage 94.04%" and "Avg Coverage 47.90%"; it does not say injection was detected in 94% of applications.
' OR '1'='1' {
This example is not valid SQL comment syntax. Major SQL dialects use `--` and `/* ... */`; MySQL’s third comment style is `#`, not `{`.
Full reasoning
The example line is incorrect because { is not a SQL comment delimiter.
Official MySQL documentation says MySQL supports three comment styles: #, -- , and /* ... */. Official SQL Server documentation likewise documents -- for single-line comments and /* ... */ for multiline comments. Neither vendor documents { as a SQL comment starter.
So this example would mislead readers about valid SQL syntax. If the intent was to show a third comment style in MySQL, the correct syntax would be #, not {.
2 sources
- MySQL :: MySQL 8.0 Reference Manual :: 11.7 Comments
MySQL says: "MySQL Server supports three comment styles" and lists `#`, `--`, and `/* ... */`.
- -- (Comment) (Transact-SQL) - SQL Server | Microsoft Learn
Microsoft documents `--` for single-line comments and refers separately to `/* ... */` for multiline comments; it does not document `{` as comment syntax.
However, a 2015 cyberattack on British telecommunications company TalkTalk exploited an SQL injection vulnerability, compromising the personal data of approximately 400,000 customers.
The confirmed number was far lower than 400,000. The UK ICO says the attacker accessed the personal data of 156,959 TalkTalk customers.
Full reasoning
This sentence overstates the scale of the TalkTalk breach. The UK Information Commissioner’s Office, which investigated the incident, states that the attack accessed the personal details of 156,959 customers, including bank account details in 15,656 cases.
That official figure also matches TalkTalk’s later public statements after the initial uncertainty around the breach. So describing the breach as compromising the personal data of approximately 400,000 customers is not supported by the final confirmed findings.
1 source
- TalkTalk cyber attack - how the ICO's investigation unfolded | ICO
The ICO says: "The attack saw the personal details of 156,959 customers accessed" and later repeats that "The attacker accessed the personal data of 156,959 customers."}]}【อ่านข้อความเต็มanalysis to=web.run codeപ്പെടുത്തി 天天中彩票不能? Let's search specific claim maybe other sources. Search for 400,000 SQL injection talktalk. Probably wrong. We already have official source. Good. Need maybe consider correction on example line with { maybe some other DBMS or systems use braces as comments? likely no. okay. Since submit_correction already called. Need stop when done. But should we further inspect other potential issues? The instruction says investigate all factual claims. But time. We can do some more quick scans for other strong falsehoods. Maybe article says