“…In the fault-based category the existing works range from the development of sets of mutants for SQL queries [17], [18] or schemas [19], [20], [21] to the evaluation of the fault-detection effectiveness with tools [22], [23], [24], [25], fault-localization [26] and empirical studies [27]. Others are application specific, mainly with the goal of detecting SQL injection vulnerabilities [28], [29], [30] and preventing them [31].…”