VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 164 of 1,043
  • CVE-2019-14231CriJul 21, 2019
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no sanitization prior to use in a SQL query in getResultByPointsTrivia. This allows…

  • CVE-2019-14230CriJul 21, 2019
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an…

  • CVE-2019-13569CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

  • CVE-2019-12193CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.01

    H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.

  • CVE-2019-1010248CriJul 18, 2019
    risk 0.64cvss 9.8epss 0.01

    Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web login form. The attack vector is: An attacker can exploit the vulnerability by sending a malicious HTTP POST request. The fixed…

  • CVE-2019-1010104CriJul 18, 2019
    risk 0.64cvss 9.8epss 0.02

    TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the database. The component is: like_escape is used in Quick-chat.php line 399. The attack vector is: Crafted ajax request.

  • CVE-2019-13575CriJul 18, 2019
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

  • CVE-2019-13447CriJul 17, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could access the backend database via SQL injection.

  • CVE-2019-13573CriJul 17, 2019
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

  • CVE-2019-13027CriJul 12, 2019
    risk 0.64cvss 9.8epss 0.03

    Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.

  • CVE-2019-13507CriJul 11, 2019
    risk 0.64cvss 9.8epss 0.02

    hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection.

  • CVE-2019-12838CriJul 11, 2019
    risk 0.64cvss 9.8epss 0.03

    SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.

  • CVE-2019-13489CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.01

    Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t parameter.

  • CVE-2019-10653CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.

  • CVE-2019-12723CriJul 10, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax/reorder.php by an unauthenticated user.

  • CVE-2019-13413CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.02

    The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.

  • CVE-2019-13275CriJul 4, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.

  • CVE-2019-12850CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.

  • CVE-2017-18346CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.

  • CVE-2019-12960CriJun 25, 2019
    risk 0.64cvss 9.8epss 0.01

    LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.