VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 279 of 1,043
  • CVE-2019-17294HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the export function by a Regular user.

  • CVE-2019-17293HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.

  • CVE-2019-17319HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.

  • CVE-2019-17318HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.

  • CVE-2015-9454HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.02

    The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter.

  • CVE-2019-12686HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-12685HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-12684HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-12683HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-12682HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-12681HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-12680HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-12679HigOct 2, 2019
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary SQL injections on an affected device. These vulnerabilities exist due to improper input…

  • CVE-2019-16745HigSep 30, 2019
    risk 0.57cvss 8.8epss 0.02

    eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.

  • CVE-2019-16744HigSep 30, 2019
    risk 0.57cvss 8.8epss 0.02

    eBrigade before 5.0 has evenements.php cid SQL Injection.

  • CVE-2019-16743HigSep 30, 2019
    risk 0.57cvss 8.8epss 0.02

    eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.

  • CVE-2015-9448HigSep 26, 2019
    risk 0.57cvss 8.8epss 0.02

    The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter.

  • CVE-2015-9446HigSep 26, 2019
    risk 0.57cvss 8.8epss 0.02

    The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php.

  • CVE-2019-16194CriSep 25, 2019
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOneService.php.

  • CVE-2015-9400HigSep 20, 2019
    risk 0.57cvss 8.8epss 0.02

    The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection.