VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 253 of 1,043
  • CVE-2021-28999HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.

  • CVE-2023-31038HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.02

    SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the database were properly escaped for SQL injection.  This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx is a C++…

  • CVE-2022-4259HigMay 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.

  • CVE-2023-29842HigMay 4, 2023
    risk 0.57cvss 8.8epss 0.01

    ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

  • CVE-2023-27568HigMay 4, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=

  • CVE-2023-31433HigMay 2, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated attackers to execute SQL statements via the welche parameter.

  • CVE-2012-5872CriApr 26, 2023
    risk 0.57cvss 9.8epss 0.01

    ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.

  • CVE-2023-30839CriApr 25, 2023
    risk 0.57cvss 9.9epss 0.02

    PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this…

  • CVE-2023-0388HigApr 24, 2023
    risk 0.57cvss 8.8epss 0.01

    The Random Text WordPress plugin through 0.3.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers.

  • CVE-2023-0765HigApr 17, 2023
    risk 0.57cvss 8.8epss 0.01

    The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin…

  • CVE-2023-29597HigApr 13, 2023
    risk 0.57cvss 8.8epss 0.01

    bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.

  • CVE-2023-26860HigApr 10, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component.

  • CVE-2020-36077HigApr 10, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the customer parameter of the orderadd.php file

  • CVE-2020-36074HigApr 6, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the title parameter.

  • CVE-2020-36073HigApr 6, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page.

  • CVE-2020-36072HigApr 6, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter.

  • CVE-2020-36071HigApr 6, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbitrary code via the customer parameter of the email.php page.

  • CVE-2023-1522HigApr 5, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in the Hardware Inventory report of Security Center 5.11.2.

  • CVE-2022-4935HigApr 5, 2023
    risk 0.57cvss 8.8epss 0.01

    The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal permissions…

  • CVE-2020-21060HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.