VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 12 of 1,041
  • CVE-2019-16894CriSep 26, 2019
    risk 0.67cvss 9.8epss 0.03

    download.php in inoERP 4.15 allows SQL injection through insecure deserialization.

  • CVE-2019-16693CriSep 22, 2019
    risk 0.67cvss 9.8epss 0.04

    phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.

  • CVE-2019-14314CriAug 27, 2019
    risk 0.67cvss 9.8epss 0.43

    A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package…

  • CVE-2019-13292CriJul 4, 2019
    risk 0.67cvss 9.8epss 0.09

    A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

  • CVE-2019-10866CriMay 23, 2019
    risk 0.67cvss 9.8epss 0.06

    In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.

  • CVE-2019-12279CriMay 22, 2019
    risk 0.67cvss 9.8epss 0.04

    Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any…

  • CVE-2019-8923CriMay 14, 2019
    risk 0.67cvss 9.8epss 0.04

    XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.

  • CVE-2018-18800CriMay 14, 2019
    risk 0.67cvss 9.8epss 0.03

    The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php.

  • CVE-2019-5722CriMar 21, 2019
    risk 0.67cvss 9.8epss 0.04

    An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.

  • CVE-2018-18798CriMar 21, 2019
    risk 0.67cvss 9.8epss 0.03

    Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.

  • CVE-2019-9184CriFeb 26, 2019
    risk 0.67cvss 9.8epss 0.09

    SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.

  • CVE-2018-13045CriJan 2, 2019
    risk 0.67cvss 9.8epss 0.03

    SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2018-18923CriDec 13, 2018
    risk 0.67cvss 9.8epss 0.03

    AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php.

  • CVE-2018-18619CriNov 29, 2018
    risk 0.67cvss 9.8epss 0.04

    internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in…

  • CVE-2018-18805CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.05

    Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.

  • CVE-2018-18804CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.03

    Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.

  • CVE-2018-18803CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.03

    Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.

  • CVE-2018-18801CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.03

    The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].

  • CVE-2018-18795CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.03

    School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.

  • CVE-2018-18763CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.03

    SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.