VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 137 of 1,043
  • CVE-2020-28102CriJan 11, 2022
    risk 0.64cvss 9.8epss 0.01

    cscms v4.1 allows for SQL injection via the "js_del" function.

  • CVE-2021-24949CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.02

    The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead to SQL injection

  • CVE-2021-45334CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.03

    Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection

  • CVE-2021-43631CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.

  • CVE-2021-43629CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

  • CVE-2021-43628CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.

  • CVE-2021-43157CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.

  • CVE-2021-43155CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.

  • CVE-2021-45255CriDec 21, 2021
    risk 0.64cvss 9.8epss 0.02

    The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted…

  • CVE-2021-45253CriDec 21, 2021
    risk 0.64cvss 9.8epss 0.01

    The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The…

  • CVE-2021-45252CriDec 21, 2021
    risk 0.64cvss 9.8epss 0.01

    Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this…

  • CVE-2021-24849CriDec 21, 2021
    risk 0.64cvss 9.8epss 0.08

    The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticated and authenticated user, does not properly sanitise multiple parameters before using them in SQL statements, leading to SQL injections

  • CVE-2021-44350CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

  • CVE-2021-42945CriDec 15, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.

  • CVE-2021-42064CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.01

    If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The…

  • CVE-2021-45014CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an upload sql injection vulnerability in the background of taocms 3.0.2 in parameter id:action=cms&ctrl=update&id=26

  • CVE-2021-44966CriDec 13, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log in as an admin account of this system and can destroy, change or manipulate all sensitive information on the system.

  • CVE-2021-24951CriDec 13, 2021
    risk 0.64cvss 9.8epss 0.02

    The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

  • CVE-2021-24863CriDec 13, 2021
    risk 0.64cvss 9.8epss 0.02

    The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before 6.67 does not sanitise and escape the User Agent before using it in a SQL statement to save it, leading to a SQL injection

  • CVE-2021-41695CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .