VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 108 of 1,043
  • CVE-2022-41403CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.

  • CVE-2022-41408CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.

  • CVE-2022-40872CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.

  • CVE-2022-40835CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability

  • CVE-2022-40834CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40833CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40832CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40831CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40830CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40829CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40828CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40827CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40826CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40825CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40824CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40943CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

  • CVE-2022-35156CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

  • CVE-2022-40944CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

  • CVE-2022-40315CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

  • CVE-2022-33880CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.