VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 102 of 1,043
  • CVE-2022-45677CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.

  • CVE-2022-45564CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet.

  • CVE-2023-23279CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.

  • CVE-2021-33948CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.

  • CVE-2020-29168CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.

  • CVE-2023-24221CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.

  • CVE-2023-24220CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.

  • CVE-2023-24219CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.

  • CVE-2021-33925CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.

  • CVE-2020-21120CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.

  • CVE-2020-21119CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.

  • CVE-2023-24084CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.

  • CVE-2022-4445CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2022-4557CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2022-45526CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.

  • CVE-2023-24201CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

  • CVE-2023-24200CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

  • CVE-2023-24199CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

  • CVE-2023-24198CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

  • CVE-2021-37497CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.