VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 132 of 1,043
  • CVE-2022-25505CriMar 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.php.

  • CVE-2021-44088CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.03

    An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.

  • CVE-2022-26293CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.

  • CVE-2022-25494CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.

  • CVE-2022-25492CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.

  • CVE-2022-25490CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.

  • CVE-2022-25488CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.07

    Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.

  • CVE-2022-0658CriMar 14, 2022
    risk 0.64cvss 9.8epss 0.09

    The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

  • CVE-2021-25007CriMar 14, 2022
    risk 0.64cvss 9.8epss 0.02

    The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection

  • CVE-2022-24607CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.

  • CVE-2022-24606CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.

  • CVE-2022-24605CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.

  • CVE-2022-24604CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.

  • CVE-2022-24603CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.

  • CVE-2022-24602CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

  • CVE-2022-24600CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.

  • CVE-2022-26201CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.

  • CVE-2022-25125CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.07

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.

  • CVE-2022-23899CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.01

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.

  • CVE-2022-23898CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.08

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.