VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 217 of 1,043
  • CVE-2022-45820CriJan 26, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

  • CVE-2022-43462CriJan 17, 2023
    risk 0.59cvss 9.1epss 0.01

    Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.

  • CVE-2022-39066HigNov 22, 2022
    risk 0.59cvss 8.8epss 0.27

    There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

  • CVE-2022-44727CriNov 10, 2022
    risk 0.59cvss 9.1epss 0.03

    The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).

  • CVE-2022-41133HigOct 27, 2022
    risk 0.59cvss 8.8epss 0.27

    The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_line_message_settingsListParameters. A low-privileged authenticated attacker could exploit this issue to inject arbitrary SQL queries.

  • CVE-2022-36635HigOct 7, 2022
    risk 0.59cvss 8.8epss 0.17

    ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.

  • CVE-2022-42302CriOct 3, 2022
    risk 0.59cvss 9.0epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.

  • CVE-2022-30998CriJul 22, 2022
    risk 0.59cvss 9.1epss 0.01

    Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.

  • CVE-2022-33128CriJun 25, 2022
    risk 0.59cvss 9.1epss 0.01

    RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_alarmAction at /alarm_pi/alarmService.php.

  • CVE-2021-41647CriOct 1, 2021
    risk 0.59cvss 9.1epss 0.02

    An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an…

  • CVE-2021-33701CriSep 15, 2021
    risk 0.59cvss 9.1epss 0.02

    DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute…

  • CVE-2021-37557HigAug 3, 2021
    risk 0.59cvss 8.8epss 0.27

    A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.

  • CVE-2021-37556HigAug 3, 2021
    risk 0.59cvss 8.8epss 0.27

    A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end…

  • CVE-2020-5320CriJul 19, 2021
    risk 0.59cvss 9.0epss 0.01

    Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to…

  • CVE-2021-21427CriApr 21, 2021
    risk 0.59cvss 9.1epss 0.01

    Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts versions before 19.4.13 and 20.0.9 potentially allows an administrator unauthorized access to restricted resources. This is a backport of CVE-2021-21024. The…

  • CVE-2021-21024CriFeb 11, 2021
    risk 0.59cvss 9.1epss 0.03

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a blind SQL injection vulnerability in the Search module. Successful exploitation could lead to unauthorized access to restricted resources by an unauthenticated attacker. Access…

  • CVE-2020-35765HigFeb 5, 2021
    risk 0.59cvss 8.8epss 0.27

    doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.

  • CVE-2020-35270CriJan 26, 2021
    risk 0.59cvss 9.1epss 0.02

    Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.

  • CVE-2021-1225CriJan 20, 2021
    risk 0.59cvss 9.1epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management interface…

  • CVE-2020-13921CriAug 5, 2020
    risk 0.59cvss 9.8epss 0.33

    **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.