VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 248 of 1,043
  • CVE-2023-48253HigJan 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values…

  • CVE-2023-50070HigDec 29, 2023
    risk 0.57cvss 8.8epss 0.01

    Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.

  • CVE-2023-5645HigDec 26, 2023
    risk 0.57cvss 8.8epss 0.01

    The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

  • CVE-2022-39822HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.

  • CVE-2023-44482HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44481HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45121HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45120HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45119HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the /update.php?q=quiz resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45118HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45117HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the /update.php?q=rmquiz resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45116HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45115HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5011HigDec 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursename' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5010HigDec 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5007HigDec 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-6035HigDec 11, 2023
    risk 0.57cvss 8.8epss 0.01

    The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

  • CVE-2023-43743HigDec 8, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter…

  • CVE-2023-48893HigDec 1, 2023
    risk 0.57cvss 8.8epss 0.01

    SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.

  • CVE-2023-48813HigDec 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.