VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 142 of 1,043
  • CVE-2020-20675CriAug 26, 2021
    risk 0.64cvss 9.8epss 0.01

    Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.

  • CVE-2020-19705CriAug 26, 2021
    risk 0.64cvss 9.8epss 0.01

    thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.

  • CVE-2021-36385CriAug 24, 2021
    risk 0.64cvss 9.8epss 0.03

    A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.

  • CVE-2021-24551CriAug 23, 2021
    risk 0.64cvss 9.8epss 0.02

    The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue

  • CVE-2021-39302CriAug 19, 2021
    risk 0.64cvss 9.8epss 0.01

    MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

  • CVE-2021-37358CriAug 18, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".

  • CVE-2020-18164CriAug 17, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.

  • CVE-2021-38754CriAug 16, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.

  • CVE-2021-38302CriAug 13, 2021
    risk 0.64cvss 9.8epss 0.01

    The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.

  • CVE-2021-36789CriAug 13, 2021
    risk 0.64cvss 9.8epss 0.01

    The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.

  • CVE-2021-28890CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.01

    J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, related to the use of ${} to join SQL statements.

  • CVE-2021-37599CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.03

    The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter.

  • CVE-2020-20975CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.01

    In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.

  • CVE-2021-38574CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.

  • CVE-2021-38167CriAug 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.

  • CVE-2021-38159CriAug 7, 2021
    risk 0.64cvss 9.8epss 0.02

    In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL…

  • CVE-2021-36351CriAug 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.

  • CVE-2021-32590CriAug 4, 2021
    risk 0.64cvss 9.9epss 0.02

    Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on…

  • CVE-2021-37558CriAug 3, 2021
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a…

  • CVE-2021-37832CriAug 3, 2021
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.