VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 106 of 1,043
  • CVE-2022-43213CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.

  • CVE-2022-43212CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.

  • CVE-2022-43215CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.

  • CVE-2022-43214CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.

  • CVE-2022-44785CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.

  • CVE-2022-39180CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page

  • CVE-2022-36787CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.

  • CVE-2022-42245CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

  • CVE-2022-44003CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

  • CVE-2022-43135CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.

  • CVE-2022-43262CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.

  • CVE-2022-43256CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

  • CVE-2022-42122CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.

  • CVE-2022-42984CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.

  • CVE-2022-43058CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.

  • CVE-2022-3481CriNov 7, 2022
    risk 0.64cvss 9.8epss 0.04

    The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

  • CVE-2022-42744CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.

  • CVE-2020-22820CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.

  • CVE-2020-22819CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.

  • CVE-2020-22818CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.