VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 149 of 1,043
  • CVE-2020-20295CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.

  • CVE-2020-20294CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.

  • CVE-2020-20289CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.01

    Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.

  • CVE-2021-3286CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.

  • CVE-2020-35263CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.02

    EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

  • CVE-2020-23262CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.

  • CVE-2021-22851CriJan 19, 2021
    risk 0.64cvss 9.8epss 0.01

    HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.

  • CVE-2020-29015CriJan 14, 2021
    risk 0.64cvss 9.8epss 0.03

    A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL…

  • CVE-2020-26712CriJan 12, 2021
    risk 0.64cvss 9.8epss 0.02

    REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability…

  • CVE-2021-3118CriJan 11, 2021
    risk 0.64cvss 9.8epss 0.02

    EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The…

  • CVE-2021-3021CriJan 5, 2021
    risk 0.64cvss 9.8epss 0.02

    ISPConfig before 3.2.2 allows SQL injection.

  • CVE-2020-26045CriJan 5, 2021
    risk 0.64cvss 9.8epss 0.02

    FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

  • CVE-2020-35245CriDec 26, 2020
    risk 0.64cvss 9.8epss 0.01

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.

  • CVE-2020-35244CriDec 26, 2020
    risk 0.64cvss 9.8epss 0.01

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.

  • CVE-2020-35243CriDec 26, 2020
    risk 0.64cvss 9.8epss 0.01

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.

  • CVE-2020-35242CriDec 26, 2020
    risk 0.64cvss 9.8epss 0.01

    Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.

  • CVE-2020-29474CriDec 24, 2020
    risk 0.64cvss 9.8epss 0.04

    EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.

  • CVE-2020-29472CriDec 24, 2020
    risk 0.64cvss 9.8epss 0.04

    EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.

  • CVE-2020-28074CriDec 23, 2020
    risk 0.64cvss 9.8epss 0.02

    SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.

  • CVE-2020-28073CriDec 23, 2020
    risk 0.64cvss 9.8epss 0.03

    SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.