VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 193 of 1,043
  • CVE-2023-26876HigApr 21, 2023
    risk 0.61cvss 8.8epss 0.10

    SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.

  • CVE-2022-41271CriDec 13, 2022
    risk 0.61cvss 9.4epss 0.01

    An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized…

  • CVE-2022-22524CriSep 28, 2022
    risk 0.61cvss 9.4epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .

  • CVE-2022-0495CriSep 21, 2022
    risk 0.61cvss 9.4epss 0.01

    The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.

  • CVE-2022-2315CriSep 21, 2022
    risk 0.61cvss 9.4epss 0.01

    Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.

  • CVE-2022-2177CriSep 20, 2022
    risk 0.61cvss 9.4epss 0.01

    Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.

  • CVE-2022-3142HigSep 19, 2022
    risk 0.61cvss 8.8epss 0.15

    The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL injections. The attack can be executed by anyone who is permitted to view the forms statistics chart, by default administrators, however…

  • CVE-2022-3141HigSep 19, 2022
    risk 0.61cvss 8.8epss 0.05

    The Translate Multilingual sites WordPress plugin before 2.3.3 is vulnerable to an authenticated SQL injection. By adding a new language (via the settings page) containing specific special characters, the backticks in the SQL query can be surpassed and a time-based blind payload…

  • CVE-2022-1277CriJul 29, 2022
    risk 0.61cvss 9.4epss 0.01

    Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.

  • CVE-2022-33965CriJul 25, 2022
    risk 0.61cvss 9.3epss 0.04

    Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

  • CVE-2021-26599CriMar 28, 2022
    risk 0.61cvss 9.8epss 0.21

    ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

  • CVE-2021-44427CriNov 29, 2021
    risk 0.61cvss 9.8epss 0.51

    An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.

  • CVE-2021-42325CriOct 12, 2021
    risk 0.61cvss 9.8epss 0.12

    Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

  • CVE-2020-7819CriSep 7, 2021
    risk 0.61cvss 9.3epss 0.01

    A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.

  • CVE-2021-31586HigJun 23, 2021
    risk 0.61cvss 8.8epss 0.44

    Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.

  • CVE-2021-28242HigApr 15, 2021
    risk 0.61cvss 8.8epss 0.05

    SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.

  • CVE-2021-28142HigApr 6, 2021
    risk 0.61cvss 8.8epss 0.06

    CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."

  • CVE-2021-27946HigMar 15, 2021
    risk 0.61cvss 8.8epss 0.04

    SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).

  • CVE-2021-27890HigMar 15, 2021
    risk 0.61cvss 8.8epss 0.11

    SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.

  • CVE-2020-35151HigDec 21, 2020
    risk 0.61cvss 8.8epss 0.04

    The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.