VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 176 of 1,043
  • CVE-2018-9924CriApr 10, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request.

  • CVE-2018-9309CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.

  • CVE-2018-9247CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.02

    The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then…

  • CVE-2014-4959CriMar 27, 2018
    risk 0.64cvss 9.8epss 0.01

    **DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.

  • CVE-2018-8967CriMar 24, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.

  • CVE-2018-8943CriMar 22, 2018
    risk 0.64cvss 9.8epss 0.01

    There is a SQL injection in the PHPSHE 1.6 userbank parameter.

  • CVE-2018-7269CriMar 21, 2018
    risk 0.64cvss 9.8epss 0.02

    The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.

  • CVE-2014-2652CriMar 19, 2018
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-7033CriMar 15, 2018
    risk 0.64cvss 9.8epss 0.02

    SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.

  • CVE-2018-1000131CriMar 14, 2018
    risk 0.64cvss 9.8epss 0.02

    Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be…

  • CVE-2018-7732CriMar 6, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in YxtCMF 3.1. SQL Injection exists in ShitiController.class.php via the ids array parameter to exam/shiti/delshiti.html.

  • CVE-2018-7666CriMar 5, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the ajax/commonAjax.php username parameter.

  • CVE-2018-7463CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2017-9426CriFeb 26, 2018
    risk 0.64cvss 9.8epss 0.03

    ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.

  • CVE-2018-6859CriFeb 23, 2018
    risk 0.64cvss 9.8epss 0.02

    SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.

  • CVE-2017-18194CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter.

  • CVE-2017-5814CriFeb 15, 2018
    risk 0.64cvss 9.8epss 0.09

    A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

  • CVE-2017-5810CriFeb 15, 2018
    risk 0.64cvss 9.8epss 0.05

    A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

  • CVE-2018-6928CriFeb 13, 2018
    risk 0.64cvss 9.8epss 0.02

    PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.

  • CVE-2018-6893CriFeb 12, 2018
    risk 0.64cvss 9.8epss 0.03

    controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and the parameter 'module' with a SQL statement, lacks effective filtering.