This information can be used by attackers to make an educated guess about the application environment type, version and state. In some situations these errors may indicate a weakness, which could be exploited via a SQL Injection attack.


It is strongly recommended to ensure that any SQL errors (and other server errors in general) are trapped and never displayed to the user. The user should only see a generic message, which contains enough information to follow up with track the error with your customer support team.