VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 151 of 1,043
  • CVE-2019-19876CriNov 27, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.

  • CVE-2020-28994CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.

  • CVE-2020-25475CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.01

    SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.

  • CVE-2020-25839CriNov 20, 2020
    risk 0.64cvss 9.8epss 0.01

    NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.

  • CVE-2020-28183CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.

  • CVE-2020-28133CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.

  • CVE-2020-28138CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.02

    SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.

  • CVE-2020-25952CriNov 16, 2020
    risk 0.64cvss 9.8epss 0.04

    SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

  • CVE-2020-13877CriNov 12, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.

  • CVE-2020-27886CriOct 29, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/functions.php file (which is called by login.php).

  • CVE-2020-27995CriOct 29, 2020
    risk 0.64cvss 9.8epss 0.09

    SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.

  • CVE-2020-26944CriOct 16, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely.

  • CVE-2020-25273CriOct 8, 2020
    risk 0.64cvss 9.8epss 0.02

    In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

  • CVE-2020-26518CriOct 2, 2020
    risk 0.64cvss 9.8epss 0.02

    Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.

  • CVE-2020-15533CriOct 1, 2020
    risk 0.64cvss 9.8epss 0.04

    In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.

  • CVE-2020-25990CriOct 1, 2020
    risk 0.64cvss 9.8epss 0.02

    WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

  • CVE-2020-12870CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.02

    RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.

  • CVE-2020-26042CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php

  • CVE-2020-20800CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.

  • CVE-2020-15487CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.04

    Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote…