VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 278 of 1,043
  • CVE-2019-5120HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially…

  • CVE-2019-5119HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially…

  • CVE-2019-5117HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Exploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,…

  • CVE-2019-5116HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause a SQL injection. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially…

  • CVE-2015-0270CriOct 25, 2019
    risk 0.57cvss 9.8epss 0.01

    Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.

  • CVE-2015-9496HigOct 22, 2019
    risk 0.57cvss 8.8epss 0.02

    The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.

  • CVE-2019-16404HigOct 21, 2019
    risk 0.57cvss 8.8epss 0.01

    Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.

  • CVE-2019-17119HigOct 17, 2019
    risk 0.57cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or subString parameter.

  • CVE-2019-10752CriOct 17, 2019
    risk 0.57cvss 9.8epss 0.01

    Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.

  • CVE-2019-17117HigOct 17, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPref.jsp key parameter.

  • CVE-2019-16917HigOct 17, 2019
    risk 0.57cvss 8.8epss 0.02

    WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain parameters are used, unsanitized, in a SQL query constructed in the buildSearchWhereClause function.

  • CVE-2015-9465HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.02

    The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.

  • CVE-2015-9460HigOct 10, 2019
    risk 0.57cvss 8.8epss 0.02

    The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.

  • CVE-2019-15016HigOct 9, 2019
    risk 0.57cvss 8.8epss 0.01

    An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the database.

  • CVE-2018-21022HigOct 8, 2019
    risk 0.57cvss 8.8epss 0.02

    makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2018-21021HigOct 8, 2019
    risk 0.57cvss 8.8epss 0.02

    img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.

  • CVE-2019-17298HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.

  • CVE-2019-17297HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user.

  • CVE-2019-17296HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user.

  • CVE-2019-17295HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.