WebPT interview question

What is sql injection and explain how it can be handled