VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 146 of 1,043
  • CVE-2021-24314CriMay 17, 2021
    risk 0.64cvss 9.8epss 0.02

    The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue

  • CVE-2021-32615CriMay 13, 2021
    risk 0.64cvss 9.8epss 0.02

    Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.

  • CVE-2020-13873CriMay 12, 2021
    risk 0.64cvss 9.8epss 0.05

    A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-reset token of the admin. (As an admin, an attacker can upload a PHP shell and…

  • CVE-2020-19114CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19112CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19110CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19109CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19108CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19107CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-22807CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.

  • CVE-2020-35430CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.

  • CVE-2020-18020CriApr 28, 2021
    risk 0.64cvss 9.8epss 0.04

    SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" component.

  • CVE-2020-27241CriApr 19, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2020-27240CriApr 19, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2020-36195CriApr 17, 2021
    risk 0.64cvss 9.8epss 0.02

    An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following…

  • CVE-2020-27239CriApr 15, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2020-27238CriApr 15, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-27237CriApr 15, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP…

  • CVE-2021-30459CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.

  • CVE-2021-27130CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.02

    Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.