VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 165 of 1,043
  • CVE-2019-13275CriJul 4, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.

  • CVE-2019-12850CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.

  • CVE-2017-18346CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.

  • CVE-2019-12960CriJun 25, 2019
    risk 0.64cvss 9.8epss 0.01

    LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.

  • CVE-2019-12939CriJun 24, 2019
    risk 0.64cvss 9.8epss 0.01

    LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.

  • CVE-2018-15868CriJun 21, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie.

  • CVE-2018-17388CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.

  • CVE-2018-17386CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.

  • CVE-2018-17381CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

  • CVE-2018-17374CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.

  • CVE-2018-17842CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.

  • CVE-2018-17841CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.

  • CVE-2018-17840CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.

  • CVE-2018-17399CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.

  • CVE-2018-17398CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.

  • CVE-2018-17393CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.

  • CVE-2018-18758CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.

  • CVE-2018-18757CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.02

    Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.

  • CVE-2019-12149CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.

  • CVE-2018-11801CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.