VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 110 of 1,043
  • CVE-2022-37204CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Final CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-38509CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.

  • CVE-2022-37203CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-40766CriSep 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.

  • CVE-2022-37138CriSep 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.

  • CVE-2022-36669CriSep 14, 2022
    risk 0.64cvss 9.8epss 0.03

    Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

  • CVE-2022-38771CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.

  • CVE-2022-38637CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.06

    Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

  • CVE-2022-38542CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above.

  • CVE-2022-38541CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.

  • CVE-2022-38540CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.

  • CVE-2022-38539CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.

  • CVE-2022-38538CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module.

  • CVE-2022-38537CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface.

  • CVE-2022-37794CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.

  • CVE-2021-44835CriSep 9, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection.

  • CVE-2022-38250CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.03

    Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

  • CVE-2020-22669CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web…

  • CVE-2022-36609CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.

  • CVE-2022-36594CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.