VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 115 of 1,043
  • CVE-2022-34946CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.

  • CVE-2022-34945CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.

  • CVE-2022-1950CriAug 1, 2022
    risk 0.64cvss 9.8epss 0.06

    The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

  • CVE-2022-22280CriJul 29, 2022
    risk 0.64cvss 9.8epss 0.10

    Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions.

  • CVE-2022-36161CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

  • CVE-2022-34989CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.

  • CVE-2022-32456CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.

  • CVE-2022-34023CriJul 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.

  • CVE-2022-27434CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.01

    UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.

  • CVE-2022-30113CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.

  • CVE-2022-29601CriJul 12, 2022
    risk 0.64cvss 9.8epss 0.01

    The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.

  • CVE-2022-29600CriJul 12, 2022
    risk 0.64cvss 9.8epss 0.01

    The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.

  • CVE-2022-1057CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.08

    The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

  • CVE-2022-28623CriJul 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL…

  • CVE-2021-35283CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.

  • CVE-2022-32056CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter at process.php.

  • CVE-2022-34972CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.02

    So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.

  • CVE-2022-32311CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.02

    Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.

  • CVE-2022-31856CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.02

    Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.

  • CVE-2022-32095CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.