Learning path

Full curriculum

Full curriculum

Unit content

Injection vulnerabilities and code-data separation

An injection vulnerability occurs when untrusted data is interpreted as instructions or syntax in a language that the application intended only to supply with data.

A dangerous pattern is conceptually

command = prefix + user_input + suffix
execute(command)

If user_input can introduce quoting, operators or delimiters understood by the target interpreter, the attacker may change the command's structure rather than merely its data values.

The robust defense is to preserve code-data separation. Structured APIs should pass data through typed or parameterized interfaces instead of constructing executable syntax by string concatenation.

Escaping can be necessary when a structured interface is unavailable, but escaping rules depend on the exact interpreter and syntactic context. Applying the wrong encoding can leave the injection intact.

SQL injection, shell-command injection and many template or expression-language bugs share this underlying failure: bytes intended as data cross a boundary and acquire executable meaning.