VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 138 of 1,043
  • CVE-2021-41063CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.

  • CVE-2021-29114CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

  • CVE-2021-31632CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.

  • CVE-2021-24943CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.07

    The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an…

  • CVE-2021-24866CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion

  • CVE-2021-43035CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible,…

  • CVE-2021-35414CriDec 3, 2021
    risk 0.64cvss 9.8epss 0.02

    Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.

  • CVE-2021-44349CriDec 3, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php.

  • CVE-2021-44348CriDec 3, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php.

  • CVE-2021-44347CriDec 3, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.

  • CVE-2021-43679CriDec 2, 2021
    risk 0.64cvss 9.8epss 0.02

    ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.

  • CVE-2021-43451CriDec 1, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.

  • CVE-2021-44280CriDec 1, 2021
    risk 0.64cvss 9.8epss 0.02

    attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.

  • CVE-2021-41679CriNov 30, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.

  • CVE-2021-41678CriNov 30, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/users/Staff.php, staff{TITLE] parameter.

  • CVE-2021-41677CriNov 30, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/functions/GetStuListFnc.php &Grade= parameter.

  • CVE-2021-41931CriNov 17, 2021
    risk 0.64cvss 9.8epss 0.01

    The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted…

  • CVE-2021-43362CriNov 16, 2021
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.

  • CVE-2021-43361CriNov 16, 2021
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1.

  • CVE-2021-41080CriNov 11, 2021
    risk 0.64cvss 9.8epss 0.05

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.