VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 166 of 1,043
  • CVE-2018-11800CriJun 11, 2019
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

  • CVE-2019-9087CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.02

    HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.

  • CVE-2019-9086CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.02

    HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.

  • CVE-2019-12601CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3).

  • CVE-2019-12600CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3).

  • CVE-2019-12599CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection.

  • CVE-2019-12598CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3).

  • CVE-2018-20091CriJun 7, 2019
    risk 0.64cvss 9.9epss 0.01

    An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in…

  • CVE-2017-14851CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.04

    A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.

  • CVE-2018-17843CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and…

  • CVE-2018-17181CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.

  • CVE-2018-12295CriMay 13, 2019
    risk 0.64cvss 9.8epss 0.01

    SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.

  • CVE-2017-12759CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.04

    Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote).

  • CVE-2017-12758CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment component.

  • CVE-2017-12757CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.04

    Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script…

  • CVE-2019-11678CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.09

    The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

  • CVE-2018-18285CriApr 25, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an attacker to extract sensitive information…

  • CVE-2018-18286CriApr 25, 2019
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface. A successful exploit could allow an attacker to extract sensitive…

  • CVE-2018-18251CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and other content being sent to the server.…

  • CVE-2019-11450CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.01

    whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection.