VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 128 of 1,043
  • CVE-2022-28028CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.

  • CVE-2022-28026CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=.

  • CVE-2022-28025CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.

  • CVE-2022-28024CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.

  • CVE-2022-28023CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.03

    Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier.

  • CVE-2022-28022CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.03

    Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item.

  • CVE-2022-27104CriApr 19, 2022
    risk 0.64cvss 9.8epss 0.01

    An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.

  • CVE-2022-0785CriApr 18, 2022
    risk 0.64cvss 9.8epss 0.09

    The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

  • CVE-2020-13567CriApr 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-26631CriApr 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter.

  • CVE-2022-27423CriApr 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.

  • CVE-2022-23865CriApr 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vulnerability, an attacker must inject '"> on the thes1 parameter.

  • CVE-2022-26651CriApr 15, 2022
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly…

  • CVE-2022-27479CriApr 13, 2022
    risk 0.64cvss 9.8epss 0.03

    Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.

  • CVE-2022-28036CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php

  • CVE-2022-28035CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php

  • CVE-2022-28034CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php

  • CVE-2022-28033CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.05

    Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

  • CVE-2022-28032CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.06

    AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php

  • CVE-2022-27473CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.