VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 143 of 1,043
  • CVE-2021-36624CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.03

    Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

  • CVE-2021-35458CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.02

    Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.

  • CVE-2021-34166CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.03

    A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.

  • CVE-2021-34165CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.03

    A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.

  • CVE-2020-21808CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.

  • CVE-2020-21806CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..

  • CVE-2020-18175CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.

  • CVE-2020-18013CriJul 30, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injextion vulnerability exists in Whatsns 4.0 via the ip parameter in index.php?admin_banned/add.htm.

  • CVE-2021-37478CriJul 26, 2021
    risk 0.64cvss 9.8epss 0.02

    In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.

  • CVE-2021-37477CriJul 26, 2021
    risk 0.64cvss 9.8epss 0.02

    In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.

  • CVE-2021-37476CriJul 26, 2021
    risk 0.64cvss 9.8epss 0.02

    In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.

  • CVE-2021-37475CriJul 26, 2021
    risk 0.64cvss 9.8epss 0.02

    In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.

  • CVE-2021-37473CriJul 26, 2021
    risk 0.64cvss 9.8epss 0.02

    In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.

  • CVE-2021-25213CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the catid parameter to subcat.php.

  • CVE-2021-25209CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_user.php .

  • CVE-2021-25205CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .

  • CVE-2021-26223CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.

  • CVE-2021-25212CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.

  • CVE-2021-26226CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.

  • CVE-2021-25202CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to \ahira\admin\inventory.php.