Second-Order SQL Injection: When Stored Input Detonates Later
Some payloads do nothing at the point of entry. They are stored safely, then read back into a second query that builds SQL by concatenation — and that is where they fire.
Practical guides to real-world web vulnerabilities, written by the team building the scanner that finds them.