VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 276 of 1,043
  • CVE-2019-16012HigMar 19, 2020
    risk 0.57cvss 8.1epss 0.54

    A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit…

  • CVE-2019-19292HigMar 10, 2020
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an SQL injection vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated…

  • CVE-2020-10190HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tablequery.php by crafting a special payload on the /datatables/data endpoint.

  • CVE-2019-20107HigMar 5, 2020
    risk 0.57cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id…

  • CVE-2019-4752HigFeb 20, 2020
    risk 0.57cvss 8.8epss 0.01

    IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete…

  • CVE-2020-8611HigFeb 14, 2020
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending…

  • CVE-2020-8841HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.

  • CVE-2019-20059HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.01

    payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the…

  • CVE-2015-3423HigFeb 8, 2020
    risk 0.57cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3, (8) param4, (9)…

  • CVE-2013-3638HigFeb 6, 2020
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.

  • CVE-2015-0244CriJan 27, 2020
    risk 0.57cvss 9.8epss 0.04

    PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter…

  • CVE-2020-7981CriJan 25, 2020
    risk 0.57cvss 9.8epss 0.01

    sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.

  • CVE-2020-7939HigJan 23, 2020
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)

  • CVE-2019-20179HigJan 9, 2020
    risk 0.57cvss 8.8epss 0.01

    SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.

  • CVE-2020-5511HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.02

    PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.

  • CVE-2013-3932HigJan 2, 2020
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to execute arbitrary SQL commands via the id parameter in an editProfile action to administrator/index.php.

  • CVE-2019-19734HigDec 30, 2019
    risk 0.57cvss 8.8epss 0.01

    _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

  • CVE-2015-3424HigDec 9, 2019
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.

  • CVE-2019-5112HigDec 3, 2019
    risk 0.57cvss 8.8epss 0.02

    Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_status was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web…

  • CVE-2019-5111HigDec 3, 2019
    risk 0.57cvss 8.8epss 0.01

    Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and parameter filter_cat was confirmed to suffer from SQL injections and could be exploited by authenticated attackers. An attacker can send a web…