VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 280 of 1,043
  • CVE-2015-9398HigSep 20, 2019
    risk 0.57cvss 8.8epss 0.02

    The gocodes plugin through 1.3.5 for WordPress has wp-admin/tools.php gcid SQL injection.

  • CVE-2015-9395HigSep 20, 2019
    risk 0.57cvss 8.8epss 0.02

    The users-ultra plugin before 1.5.64 for WordPress has SQL Injection via an ajax action.

  • CVE-2019-12516HigSep 13, 2019
    risk 0.57cvss 8.8epss 0.02

    The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-admin/admin.php?page=slickquiz-scores&id= or /wp-admin/admin.php?page=slickquiz-edit&id= or /wp-admin/admin.php?page=slickquiz-preview&id= URI.

  • CVE-2016-10950HigSep 13, 2019
    risk 0.57cvss 8.8epss 0.02

    The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.

  • CVE-2016-10949HigSep 13, 2019
    risk 0.57cvss 8.8epss 0.02

    The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.

  • CVE-2016-10942CriSep 13, 2019
    risk 0.57cvss 9.8epss 0.02

    The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.

  • CVE-2019-5996HigSep 12, 2019
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2017-18602HigSep 10, 2019
    risk 0.57cvss 8.8epss 0.02

    The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.

  • CVE-2017-18597HigSep 10, 2019
    risk 0.57cvss 8.8epss 0.02

    The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.

  • CVE-2019-10671HigSep 9, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php…

  • CVE-2019-15570CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.01

    BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.

  • CVE-2019-15563CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.02

    Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.

  • CVE-2019-12385HigAug 22, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to…

  • CVE-2017-18515CriAug 14, 2019
    risk 0.57cvss 9.8epss 0.03

    The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.

  • CVE-2019-14966HigAug 12, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.

  • CVE-2019-14266HigJul 25, 2019
    risk 0.57cvss 8.8epss 0.01

    OpenSNS v6.1.0 allows SQL Injection via the index.php?s=/ucenter/Config/ uid parameter because of the getNeedQueryData function in Application/Common/Model/UserModel.class.php.

  • CVE-2019-13978HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.01

    Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request.

  • CVE-2019-13969HigJul 19, 2019
    risk 0.57cvss 8.8epss 0.01

    Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.

  • CVE-2019-1010259CriJul 18, 2019
    risk 0.57cvss 9.8epss 0.02

    SaltStack Salt 2018.3, 2019.2 is affected by: SQL Injection. The impact is: An attacker could escalate privileges on MySQL server deployed by cloud provider. It leads to RCE. The component is: The mysql.user_chpass function from the MySQL module for Salt. The attack vector is:…

  • CVE-2018-13442HigJul 16, 2019
    risk 0.57cvss 8.8epss 0.02

    SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.