VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 144 of 1,043
  • CVE-2020-36033CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.

  • CVE-2021-26232CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.

  • CVE-2021-26231CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.

  • CVE-2021-26229CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.

  • CVE-2021-26228CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.

  • CVE-2021-26765CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.

  • CVE-2020-35427CriJul 20, 2021
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

  • CVE-2020-18144CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.

  • CVE-2021-33578CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.01

    Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data.

  • CVE-2021-24385CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.03

    The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL…

  • CVE-2020-18544CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".

  • CVE-2020-21133CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.

  • CVE-2020-21132CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.

  • CVE-2021-24007CriJul 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

  • CVE-2020-23711CriJun 28, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.

  • CVE-2021-35456CriJun 28, 2021
    risk 0.64cvss 9.8epss 0.02

    Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload

  • CVE-2021-35048CriJun 25, 2021
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and…

  • CVE-2020-18667CriJun 24, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.

  • CVE-2020-20392CriJun 23, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.

  • CVE-2021-24361CriJun 21, 2021
    risk 0.64cvss 9.8epss 0.02

    In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.