VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 153 of 1,043
  • CVE-2020-6141CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.04

    An exploitable SQL injection vulnerability exists in the login functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can lead to SQL injection. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-5624CriAug 28, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2020-23979CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.

  • CVE-2020-23978CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"

  • CVE-2020-23976CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.

  • CVE-2020-23973CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.

  • CVE-2020-23980CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.

  • CVE-2020-23936CriAug 20, 2020
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".

  • CVE-2020-24208CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.

  • CVE-2020-8211CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

  • CVE-2020-12606CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web frontend allows an attacker to run arbitrary SQL commands on the SQL Server. Command execution can be easily achieved by using the…

  • CVE-2020-16165CriJul 30, 2020
    risk 0.64cvss 9.8epss 0.01

    The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.

  • CVE-2020-14497CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.05

    Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely…

  • CVE-2020-13926CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous…

  • CVE-2020-15504CriJul 10, 2020
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13…

  • CVE-2020-8521CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql

  • CVE-2020-8520CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql

  • CVE-2020-8519CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql

  • CVE-2019-20896CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

  • CVE-2020-15540CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.