VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 281 of 1,043
  • CVE-2019-11512CriJul 9, 2019
    risk 0.57cvss 9.8epss 0.01

    Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.

  • CVE-2019-12570HigJul 3, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET parameters.

  • CVE-2019-9846HigJun 28, 2019
    risk 0.57cvss 8.8epss 0.02

    RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WHERE clause unsafely by using the pidfields and idfields parameters, aka background SQL injection.

  • CVE-2019-9039CriJun 26, 2019
    risk 0.57cvss 9.8epss 0.03

    In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint.…

  • CVE-2019-4224HigJun 26, 2019
    risk 0.57cvss 8.8epss 0.01

    IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 159240.

  • CVE-2018-16116HigJun 20, 2019
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "username" GET parameter.

  • CVE-2019-11984HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11979HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11978HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11977HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11976HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11975HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11974HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11973HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11972HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11971HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11970HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-11768CriJun 5, 2019
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in phpMyAdmin before 4.9.0.1. A vulnerability was reported where a specially crafted database name can be used to trigger an SQL injection attack through the designer feature.

  • CVE-2016-10755HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.01

    AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.

  • CVE-2016-10754HigMay 24, 2019
    risk 0.57cvss 8.8epss 0.01

    modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.