VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 11 of 1,041
  • CVE-2021-24442CriJul 12, 2021
    risk 0.67cvss 9.8epss 0.46

    The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

  • CVE-2020-18662CriJun 24, 2021
    risk 0.67cvss 9.8epss 0.05

    SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

  • CVE-2020-24913CriMar 4, 2021
    risk 0.67cvss 9.8epss 0.41

    A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.

  • CVE-2020-35846CriDec 30, 2020
    risk 0.67cvss 9.8epss 0.93

    Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.

  • CVE-2020-15468CriJul 1, 2020
    risk 0.67cvss 9.8epss 0.03

    Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.

  • CVE-2020-15363CriJun 28, 2020
    risk 0.67cvss 9.8epss 0.06

    The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

  • CVE-2020-10549CriJun 4, 2020
    risk 0.67cvss 9.8epss 0.32

    rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

  • CVE-2020-10548CriJun 4, 2020
    risk 0.67cvss 9.8epss 0.37

    rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

  • CVE-2020-10547CriJun 4, 2020
    risk 0.67cvss 9.8epss 0.37

    rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

  • CVE-2020-13118CriMay 16, 2020
    risk 0.67cvss 9.8epss 0.04

    An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

  • CVE-2014-9613CriFeb 19, 2020
    risk 0.67cvss 9.8epss 0.04

    Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php.

  • CVE-2014-9612CriFeb 19, 2020
    risk 0.67cvss 9.8epss 0.05

    SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.

  • CVE-2012-1124CriFeb 11, 2020
    risk 0.67cvss 9.8epss 0.04

    SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.

  • CVE-2013-5945CriFeb 11, 2020
    risk 0.67cvss 9.8epss 0.10

    Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to…

  • CVE-2011-4094CriJan 21, 2020
    risk 0.67cvss 9.8epss 0.03

    Jara 1.6 has a SQL injection vulnerability.

  • CVE-2005-4891CriJan 15, 2020
    risk 0.67cvss 9.8epss 0.02

    Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.

  • CVE-2012-1259CriJan 9, 2020
    risk 0.67cvss 9.8epss 0.04

    Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to…

  • CVE-2019-19740CriDec 12, 2019
    risk 0.67cvss 9.8epss 0.06

    Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.

  • CVE-2019-19245CriDec 2, 2019
    risk 0.67cvss 9.8epss 0.08

    NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.

  • CVE-2011-1939CriNov 26, 2019
    risk 0.67cvss 9.8epss 0.04

    SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.