VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 174 of 1,043
  • CVE-2018-10197CriJul 11, 2018
    risk 0.64cvss 9.8epss 0.01

    There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before 10.18.040 in ELO ELOenterprise 9 and 10 and ELOprofessional 9 and 10 that makes it possible to read all database content. The vulnerability exists in the…

  • CVE-2018-13850CriJul 10, 2018
    risk 0.64cvss 9.8epss 0.01

    The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter.

  • CVE-2013-3000CriJul 9, 2018
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116.

  • CVE-2017-11088CriJul 6, 2018
    risk 0.64cvss 9.8epss 0.01

    Improper Input Validation in Linux io-prefetch in Snapdragon Mobile and Snapdragon Wear, A SQL injection vulnerability exists in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 835, SD 845.

  • CVE-2018-13116CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.01

    /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.

  • CVE-2018-11589CriJun 25, 2018
    risk 0.64cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in…

  • CVE-2018-12630CriJun 21, 2018
    risk 0.64cvss 9.8epss 0.02

    NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.

  • CVE-2015-4043CriJun 19, 2018
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands via the ctl00$cphMainContent$txtUserName parameter to frmLogin.aspx.

  • CVE-2018-9029CriJun 18, 2018
    risk 0.64cvss 9.8epss 0.02

    An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.

  • CVE-2018-12534CriJun 18, 2018
    risk 0.64cvss 9.8epss 0.01

    A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.

  • CVE-2018-10997CriJun 17, 2018
    risk 0.64cvss 9.8epss 0.02

    Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassword.

  • CVE-2018-12498CriJun 15, 2018
    risk 0.64cvss 9.8epss 0.01

    spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.

  • CVE-2017-18291CriJun 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.

  • CVE-2017-18290CriJun 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter.

  • CVE-2017-18289CriJun 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.

  • CVE-2017-18288CriJun 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter.

  • CVE-2017-18287CriJun 12, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter.

  • CVE-2018-0225CriJun 8, 2018
    risk 0.64cvss 9.8epss 0.01

    The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Security Advisory 2089 issue.

  • CVE-2018-12039CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.05

    joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a select substring.

  • CVE-2018-0320CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the web framework code of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation on user-supplied input in SQL queries. An attacker…