VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 259 of 1,043
  • CVE-2022-36688HigAug 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockout&month=.

  • CVE-2022-36686HigAug 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockin&month=.

  • CVE-2022-36704HigAug 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /librarian/studentdetails.php.

  • CVE-2022-36529HigAug 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at /framework/mod/db/DBMapper.xml.

  • CVE-2022-36721HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Textbook parameter at /admin/modify.php.

  • CVE-2022-36720HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/modify1.php.

  • CVE-2022-36703HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /stocks/manage_stockin.php.

  • CVE-2022-36701HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/view_item.php.

  • CVE-2022-36700HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php.

  • CVE-2022-36699HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/manage_category.php.

  • CVE-2022-36698HigAug 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php.

  • CVE-2022-37178HigAug 24, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar.

  • CVE-2022-37333HigAug 24, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute…

  • CVE-2022-34652HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.01

    A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in…

  • CVE-2022-33149HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.02

    A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in…

  • CVE-2022-33148HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.01

    A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in…

  • CVE-2022-33147HigAug 22, 2022
    risk 0.57cvss 8.8epss 0.02

    A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in…

  • CVE-2022-34928HigAug 3, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

  • CVE-2022-31181CriAug 1, 2022
    risk 0.57cvss 9.8epss 0.07

    PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised…

  • CVE-2022-34557HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php.