VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 135 of 1,043
  • CVE-2021-46444CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_group_edit&agID.

  • CVE-2021-41609CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.02

    SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.

  • CVE-2022-22294CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account.

  • CVE-2020-25905CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.

  • CVE-2021-45435CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.

  • CVE-2021-44249CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.

  • CVE-2021-46427CriJan 27, 2022
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

  • CVE-2021-46377CriJan 27, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser

  • CVE-2021-45802CriJan 25, 2022
    risk 0.64cvss 9.8epss 0.01

    MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

  • CVE-2021-46451CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.

  • CVE-2021-43420CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2021-41928CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.02

    SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.

  • CVE-2021-41660CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.

  • CVE-2021-41659CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.

  • CVE-2021-41472CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.

  • CVE-2021-41471CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.

  • CVE-2021-40908CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2021-40907CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php.

  • CVE-2021-40596CriJan 24, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.

  • CVE-2021-46024CriJan 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.