VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 147 of 1,043
  • CVE-2020-27236CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-27235CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-27234CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-27233CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2021-30175CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.09

    ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

  • CVE-2020-23763CriApr 9, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

  • CVE-2021-28925CriApr 8, 2021
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.

  • CVE-2021-30177CriApr 7, 2021
    risk 0.64cvss 9.8epss 0.02

    There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to be two letters, and the OrderBy field is not validated to be one of LASTNAME, CITY, or STATE.

  • CVE-2021-30000CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and code execution.

  • CVE-2020-28172CriMar 31, 2021
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.

  • CVE-2021-28668CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.01

    Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities.

  • CVE-2020-10582CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.02

    A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.

  • CVE-2020-35337CriMar 24, 2021
    risk 0.64cvss 9.8epss 0.02

    ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.

  • CVE-2020-6577CriMar 19, 2021
    risk 0.64cvss 9.8epss 0.02

    The IT-Recht Kanzlei plugin in Zen Cart 1.5.6c (German edition) allows itrk-api.php rechtstext_language SQL Injection.

  • CVE-2021-24139CriMar 18, 2021
    risk 0.64cvss 9.8epss 0.06

    Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

  • CVE-2021-22859CriMar 17, 2021
    risk 0.64cvss 9.8epss 0.04

    The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remote attackers can inject SQL syntax and execute arbitrary commands without privilege.

  • CVE-2021-28381CriMar 16, 2021
    risk 0.64cvss 9.8epss 0.01

    The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.

  • CVE-2020-24877CriMar 15, 2021
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.

  • CVE-2020-24791CriMar 10, 2021
    risk 0.64cvss 9.8epss 0.03

    FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

  • CVE-2021-27581CriMar 5, 2021
    risk 0.64cvss 9.8epss 0.02

    The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.