VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 242 of 1,043
  • CVE-2024-9968HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The affected product is no longer maintained. It is recommended to upgrade to the new…

  • CVE-2024-48813HigOct 11, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in employee-management-system-php-and-mysql-free-download.html taskmatic 1.0 allows a remote attacker to execute arbitrary code via the admin_id parameter of the /update-employee.php component.

  • CVE-2024-9286HigOct 9, 2024
    risk 0.57cvss —epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Distant Education Platform allows SQL Injection, Parameter Injection. This issue affects Distant Education Platform: before 3.2024.11.

  • CVE-2024-41512HigOct 4, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.

  • CVE-2024-9018HigOct 1, 2024
    risk 0.57cvss 8.8epss 0.01

    The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2024-8621CriSep 25, 2024
    risk 0.57cvss 9.9epss 0.01

    The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2024-5958HigSep 18, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection. This issue affects Panel: before v2.3.24.

  • CVE-2024-42404HigSep 18, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database.

  • CVE-2024-8749HigSep 12, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/modules/api/model/cmdb/isys_api_model_cmdb_objects_by_relation.class.php and retrieve all the…

  • CVE-2023-50360HigSep 6, 2024
    risk 0.57cvss 8.8epss 0.00

    A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.1 ( 2024/02/26 )…

  • CVE-2024-44739HigSep 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.

  • CVE-2024-44587HigSep 5, 2024
    risk 0.57cvss 8.8epss 0.01

    itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.

  • CVE-2024-44817HigSep 4, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.

  • CVE-2024-7871HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.

  • CVE-2024-43776HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.

  • CVE-2024-43775HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.

  • CVE-2024-43774HigSep 2, 2024
    risk 0.57cvss 8.8epss 0.00

    SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.

  • CVE-2024-7717HigAug 31, 2024
    risk 0.57cvss 8.8epss 0.01

    The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2024-8329HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.

  • CVE-2024-8327HigAug 30, 2024
    risk 0.57cvss 8.8epss 0.01

    Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.