VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 157 of 1,043
  • CVE-2020-6960CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.01

    The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6…

  • CVE-2016-11018CriJan 21, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

  • CVE-2020-7229CriJan 21, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php.

  • CVE-2011-2715CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

  • CVE-2011-5020CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.

  • CVE-2014-4984CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.03

    Déjà Vu Crescendo Sales CRM has remote SQL Injection

  • CVE-2019-4651CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.

  • CVE-2011-5266CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.01

    Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.

  • CVE-2020-5510CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.02

    PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.

  • CVE-2020-5841CriJan 7, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.

  • CVE-2019-7478CriDec 31, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.

  • CVE-2019-18234CriDec 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-17527CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.01

    dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter.

  • CVE-2019-19846CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.02

    In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

  • CVE-2019-15933CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp has SQL Injection.

  • CVE-2014-7257CriDec 11, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in DBD::PgPP 0.05 and earlier

  • CVE-2019-19649CriDec 11, 2019
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.

  • CVE-2013-2745CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

  • CVE-2011-1933CriNov 26, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in Jifty::DBI before 0.68.

  • CVE-2011-3584CriNov 26, 2019
    risk 0.64cvss 9.8epss 0.01

    The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.