VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 139 of 1,043
  • CVE-2021-24731CriNov 8, 2021
    risk 0.64cvss 9.8epss 0.06

    The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an…

  • CVE-2021-42077CriNov 8, 2021
    risk 0.64cvss 9.8epss 0.03

    PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database…

  • CVE-2021-34684CriNov 8, 2021
    risk 0.64cvss 9.8epss 0.06

    Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.

  • CVE-2020-22226CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.

  • CVE-2020-22225CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.

  • CVE-2020-22223CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.01

    Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.

  • CVE-2021-42670CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.08

    A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to…

  • CVE-2021-42668CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.05

    A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a…

  • CVE-2021-42665CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.05

    An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.

  • CVE-2021-41492CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.02

    Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.

  • CVE-2020-18262CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.01

    ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.

  • CVE-2020-24000CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.

  • CVE-2021-43130CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.

  • CVE-2020-23685CriNov 2, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.

  • CVE-2021-26739CriNov 1, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.

  • CVE-2021-41676CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.

  • CVE-2021-41674CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.

  • CVE-2020-21250CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.01

    CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.

  • CVE-2020-24932CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

  • CVE-2021-37371CriOct 26, 2021
    risk 0.64cvss 9.8epss 0.02

    Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.