Yes sir t is possible. SQL injection is a type of application layer attack technique used by hackers, where malicious SQL statements are put inside an entry field for execution. In an SQL injection attack an attacker can get critical information from the server database and hence should be taken seriously from a security point of view. In this the attacker takes the advantage of loopholes present in the web applications. To prevent injections of special characters, or they should be properly handled or skipped from the input.

SQL Injection Testing should be done for:

• Apostrophes
• Brackets
• Commas
• Quotation marks

