VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 270 of 1,043
  • CVE-2020-18155CriJul 14, 2021
    risk 0.57cvss 9.8epss 0.01

    SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.

  • CVE-2021-29730HigJul 9, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 201164.

  • CVE-2021-34609HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.01

    A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-27950HigJul 2, 2021
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to execute arbitrary SQL commands via the id parameter to mesdocs.ajax.php in azurWebEngine/eShop. By default, the query is executed as DBA.

  • CVE-2020-4902HigJul 1, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191045.

  • CVE-2021-28423HigJul 1, 2021
    risk 0.57cvss 8.8epss 0.03

    Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in…

  • CVE-2020-21394HigJun 29, 2021
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.

  • CVE-2021-24341HigJun 14, 2021
    risk 0.57cvss 8.8epss 0.02

    When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_number POST parameters are not sanitised, escaped or validated before being used in a SQL statement, leading to SQL injection.

  • CVE-2020-24671HigJun 10, 2021
    risk 0.57cvss 8.8epss 0.01

    Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

  • CVE-2020-24667HigJun 10, 2021
    risk 0.57cvss 8.8epss 0.01

    Trace Financial CRESTBridge <6.3.0.02 contains an authenticated SQL injection vulnerability, which was fixed in 6.3.0.03.

  • CVE-2021-33894HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in…

  • CVE-2021-24337HigJun 7, 2021
    risk 0.57cvss 8.8epss 0.02

    The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.

  • CVE-2020-26668HigJun 1, 2021
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed' function.

  • CVE-2020-26677HigMay 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API.

  • CVE-2021-30081HigMay 24, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement and query server sensitive data via admin/navbar.php?action=add_page.

  • CVE-2020-4990HigMay 24, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Security Guardium 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 192710.

  • CVE-2021-31827HigMay 18, 2021
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL,…

  • CVE-2021-29053HigMay 17, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2)…

  • CVE-2020-27246HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP…

  • CVE-2020-27245HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request…