VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 186 of 1,043
  • CVE-2016-9481CriNov 29, 2016
    risk 0.64cvss 9.8epss 0.02

    In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCommentControllercontroller with the parameter '$this->params['content_id']' used directly in SQL.…

  • CVE-2016-9287CriNov 15, 2016
    risk 0.64cvss 9.8epss 0.01

    In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.

  • CVE-2016-8902CriNov 14, 2016
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.

  • CVE-2016-9288CriNov 11, 2016
    risk 0.64cvss 9.8epss 0.01

    In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropReRank" is directly used without any filtration which caused SQL injection. The payload can be used like this:…

  • CVE-2016-7453CriNov 3, 2016
    risk 0.64cvss 9.8epss 0.01

    The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection.

  • CVE-2016-1000217CriOct 6, 2016
    risk 0.64cvss 9.8epss 0.06

    Zotpress plugin for WordPress SQLi in zp_get_account()

  • CVE-2016-1000113CriOct 6, 2016
    risk 0.64cvss 9.8epss 0.03

    XSS and SQLi in huge IT gallery v1.1.5 for Joomla

  • CVE-2015-1000011CriOct 6, 2016
    risk 0.64cvss 9.8epss 0.03

    Blind SQL Injection in wordpress plugin dukapress v2.5.9

  • CVE-2015-1000003CriOct 6, 2016
    risk 0.64cvss 9.8epss 0.03

    Blind SQL Injection in filedownload v1.4 wordpress plugin

  • CVE-2016-5048CriAug 26, 2016
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in chat/staff/default.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary SQL commands via the user name field.

  • CVE-2016-5817CriAug 22, 2016
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in news pages in Cargotec Navis WebAccess before 2016-08-10 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-5792CriAug 8, 2016
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.

  • CVE-2016-4999CriAug 5, 2016
    risk 0.64cvss 9.8epss 0.04

    SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set…

  • CVE-2016-4837CriAug 1, 2016
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-4522CriJul 28, 2016
    risk 0.64cvss 9.8epss 0.06

    SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-5703CriJul 3, 2016
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in libraries/central_columns.lib.php in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allows remote attackers to execute arbitrary SQL commands via a crafted database name that is mishandled in a central column query.

  • CVE-2016-0224CriJun 28, 2016
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2015-7695CriJun 7, 2016
    risk 0.64cvss 9.8epss 0.03

    The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.

  • CVE-2016-2351CriMay 7, 2016
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in home/seos/courier/security_key2.api on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote attackers to execute arbitrary SQL commands via the client_id parameter.

  • CVE-2016-4351CriMay 5, 2016
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.