VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 170 of 1,043
  • CVE-2018-1000871CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the database records of backend webserver. This attack appear to be exploitable via…

  • CVE-2018-1000869CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vulnerability to access information he/she does not have access to.. This…

  • CVE-2018-19925CriDec 6, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.

  • CVE-2018-19893CriDec 6, 2018
    risk 0.64cvss 9.8epss 0.01

    SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.

  • CVE-2018-19559CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.01

    CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.

  • CVE-2018-19558CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.

  • CVE-2018-19557CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.

  • CVE-2018-19468CriNov 23, 2018
    risk 0.64cvss 9.8epss 0.01

    HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the user/index.php?load=login&act=act_login URI.

  • CVE-2018-18806CriNov 16, 2018
    risk 0.64cvss 9.8epss 0.02

    School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.

  • CVE-2018-18796CriNov 16, 2018
    risk 0.64cvss 9.8epss 0.02

    Library Management System 1.0 has SQL Injection via the "Search for Books" screen.

  • CVE-2018-19281CriNov 14, 2018
    risk 0.64cvss 9.8epss 0.02

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.

  • CVE-2018-16850CriNov 13, 2018
    risk 0.64cvss 9.8epss 0.05

    postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

  • CVE-2018-19221CriNov 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter.

  • CVE-2018-19061CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.

  • CVE-2018-18963CriNov 6, 2018
    risk 0.64cvss 9.8epss 0.02

    Busca.aspx.cs in Degrau Publicidade e Internet Plataforma de E-commerce allows SQL Injection via the busca/ URI.

  • CVE-2018-18887CriNov 1, 2018
    risk 0.64cvss 9.8epss 0.01

    S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).

  • CVE-2018-18832CriOct 30, 2018
    risk 0.64cvss 9.8epss 0.01

    admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.

  • CVE-2018-18822CriOct 30, 2018
    risk 0.64cvss 9.8epss 0.02

    Grapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter.

  • CVE-2018-18792CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.

  • CVE-2018-18791CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.