Vulnerability where attacker can interfere with the SQL queries that an application makes to a database.
CIA triad is impacted Confidentilaity: view sensitive information Integrity: alter data in database Avaulability: Delete data in database
RCE to operating system
Same communication channel is used for attack and result of attack
Database generating error gives attaker information upon injection
Using the UNION SQL operator to combine the results of two queries into a single result set.
No actual data is tranfered via webapp asking yes or no qustions