VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 134 of 1,043
  • CVE-2022-22880CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.

  • CVE-2021-3242CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.

  • CVE-2022-23358CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.

  • CVE-2022-24206CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

  • CVE-2022-23902CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter.

  • CVE-2022-23337CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.

  • CVE-2022-23336CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.

  • CVE-2022-23335CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.

  • CVE-2022-22295CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.

  • CVE-2021-34235CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.

  • CVE-2022-23379CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().

  • CVE-2022-24222CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.01

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.

  • CVE-2022-24221CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.01

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.

  • CVE-2022-24220CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.01

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.

  • CVE-2022-24219CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.01

    eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

  • CVE-2021-43510CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.08

    SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.

  • CVE-2021-43509CriFeb 1, 2022
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.

  • CVE-2021-46448CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.

  • CVE-2021-46446CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.

  • CVE-2021-46445CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.