VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 258 of 1,043
  • CVE-2022-23695HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…

  • CVE-2022-23694HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…

  • CVE-2022-23693HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…

  • CVE-2022-23692HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…

  • CVE-2022-37205HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.02

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-23767HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.01

    This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing…

  • CVE-2022-38618HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.01

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.

  • CVE-2022-2958HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.01

    The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections

  • CVE-2022-38617HigSep 19, 2022
    risk 0.57cvss 8.8epss 0.01

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.

  • CVE-2022-38808HigSep 16, 2022
    risk 0.57cvss 8.8epss 0.01

    ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.

  • CVE-2022-37201HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.02

    JFinal CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-37207HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.02

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection

  • CVE-2022-39817HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected)…

  • CVE-2022-34700HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.04

    Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

  • CVE-2022-38616HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.

  • CVE-2022-38615HigSep 9, 2022
    risk 0.57cvss 8.8epss 0.01

    SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.

  • CVE-2022-36636HigSep 2, 2022
    risk 0.57cvss 8.8epss 0.01

    Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.

  • CVE-2022-38118HigAug 30, 2022
    risk 0.57cvss 8.8epss 0.02

    OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service.

  • CVE-2022-36690HigAug 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.

  • CVE-2022-36689HigAug 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=.