VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 131 of 1,043
  • CVE-2022-26013CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.09

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25980CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25880CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-0923CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-0846CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.09

    The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

  • CVE-2022-0787CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.09

    The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

  • CVE-2021-25070CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

  • CVE-2022-23882CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.

  • CVE-2021-44617CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

  • CVE-2022-26268CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.

  • CVE-2022-26301CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.01

    TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.

  • CVE-2021-43084CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.

  • CVE-2021-43700CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

  • CVE-2022-25222CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.02

    Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.

  • CVE-2021-43735CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.

  • CVE-2022-25517CriMar 22, 2022
    risk 0.64cvss 9.8epss 0.02

    MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.

  • CVE-2022-26285CriMar 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

  • CVE-2022-26284CriMar 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

  • CVE-2022-26283CriMar 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

  • CVE-2022-0694CriMar 21, 2022
    risk 0.64cvss 9.8epss 0.02

    The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an…