VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 163 of 1,043
  • CVE-2015-9315CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The newstatpress plugin before 1.0.1 for WordPress has SQL injection.

  • CVE-2015-9313CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.

  • CVE-2015-9301CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The liveforms plugin before 3.2.0 for WordPress has SQL injection.

  • CVE-2019-14968CriAug 12, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.

  • CVE-2019-14801CriAug 9, 2019
    risk 0.64cvss 9.8epss 0.02

    The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.

  • CVE-2019-14754CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.02

    Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.

  • CVE-2019-5476CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.

  • CVE-2019-14702CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. SQL injection vulnerabilities exist in 13 forms that are reachable through HTTPD. An attacker can, for example, create an admin account.

  • CVE-2019-14695CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers…

  • CVE-2016-10817CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.02

    cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).

  • CVE-2019-13572CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.02

    The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.

  • CVE-2018-20887CriAug 1, 2019
    risk 0.64cvss 9.8epss 0.01

    cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).

  • CVE-2019-5454CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.

  • CVE-2019-13026CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.01

    OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.

  • CVE-2019-14313CriJul 30, 2019
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.

  • CVE-2019-13571CriJul 29, 2019
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

  • CVE-2019-9885CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.03

    eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.

  • CVE-2019-1010191CriJul 24, 2019
    risk 0.64cvss 9.8epss 0.01

    marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a…

  • CVE-2019-1010153CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.

  • CVE-2019-1010148CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.