VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 13 of 1,041
  • CVE-2018-18755CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.03

    K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.

  • CVE-2015-4633CriOct 18, 2018
    risk 0.67cvss 9.8epss 0.06

    Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2)…

  • CVE-2018-17428CriOct 3, 2018
    risk 0.67cvss 9.8epss 0.03

    An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.

  • CVE-2018-17397CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.

  • CVE-2018-17394CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.

  • CVE-2018-17391CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.

  • CVE-2018-17385CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.

  • CVE-2018-17384CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.

  • CVE-2018-17383CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.

  • CVE-2018-17382CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.

  • CVE-2018-17380CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.

  • CVE-2018-17379CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

  • CVE-2018-17378CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.

  • CVE-2018-17377CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.

  • CVE-2018-17376CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.

  • CVE-2018-17375CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.

  • CVE-2018-16659CriSep 28, 2018
    risk 0.67cvss 9.8epss 0.03

    An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.

  • CVE-2018-14592CriSep 20, 2018
    risk 0.67cvss 9.8epss 0.03

    The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.

  • CVE-2018-14418CriJul 20, 2018
    risk 0.67cvss 9.8epss 0.09

    In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.

  • CVE-2018-13050CriJul 2, 2018
    risk 0.67cvss 9.8epss 0.40

    A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.