VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 282 of 1,043
  • CVE-2016-8898CriMay 24, 2019
    risk 0.57cvss 9.8epss 0.02

    Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.

  • CVE-2019-10852HigMay 23, 2019
    risk 0.57cvss 8.8epss 0.02

    Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.php?m=servers&a=start_pulling&id= substring.

  • CVE-2016-8897CriMay 23, 2019
    risk 0.57cvss 9.8epss 0.02

    Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.

  • CVE-2019-12251HigMay 21, 2019
    risk 0.57cvss 8.8epss 0.01

    sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.

  • CVE-2019-11057HigMay 17, 2019
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL commands.

  • CVE-2019-10913CriMay 16, 2019
    risk 0.57cvss 9.8epss 0.02

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is…

  • CVE-2019-10910CriMay 16, 2019
    risk 0.57cvss 9.8epss 0.06

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

  • CVE-2019-10916HigMay 14, 2019
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 (All versions < V8.1 with WinCC V7.3 Upd 19), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1 with WinCC V7.4 SP1 Upd11), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP2 with WinCC…

  • CVE-2018-16137HigMay 13, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Web Management Console in IPBRICK OS 6.3. There are multiple SQL injections.

  • CVE-2017-12760HigMay 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Ynet Interactive - http://demo.ynetinteractive.com/mobiketa/ Mobiketa 4.0 is affected by: SQL Injection. The impact is: Code execution (remote).

  • CVE-2018-14874HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp and /references/refbranu.jsp is mishandled before being used in SQL queries,…

  • CVE-2017-16558CriApr 25, 2019
    risk 0.57cvss 9.8epss 0.02

    Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

  • CVE-2018-6330HigMar 28, 2019
    risk 0.57cvss 8.8epss 0.02

    Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.

  • CVE-2019-6491HigMar 21, 2019
    risk 0.57cvss 8.8epss 0.01

    RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.

  • CVE-2019-9693HigMar 11, 2019
    risk 0.57cvss 8.8epss 0.01

    In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id),…

  • CVE-2018-17415HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.01

    zzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.

  • CVE-2018-17414HigMar 7, 2019
    risk 0.57cvss 8.8epss 0.01

    zzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.

  • CVE-2019-7164CriFeb 20, 2019
    risk 0.57cvss 9.8epss 0.04

    SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

  • CVE-2019-8429CriFeb 18, 2019
    risk 0.57cvss 9.8epss 0.02

    ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.

  • CVE-2019-8428CriFeb 18, 2019
    risk 0.57cvss 9.8epss 0.02

    ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.