VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 285 of 1,043
  • CVE-2018-11643HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter.

  • CVE-2018-7774HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input parameter.

  • CVE-2018-7773HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.

  • CVE-2018-7772HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine whether a user is logged in is subject to SQL injection on the…

  • CVE-2018-7769HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

  • CVE-2018-7768HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.

  • CVE-2018-7767HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter.

  • CVE-2018-7766HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

  • CVE-2018-7765HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.03

    The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.

  • CVE-2018-13049HigJul 2, 2018
    risk 0.57cvss 8.8epss 0.01

    The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.

  • CVE-2018-1000552HigJun 26, 2018
    risk 0.57cvss 8.8epss 0.01

    Trovebox version <= 4.0.0-rc6 contains a SQL Injection vulnerability in album component that can result in SQL code injection. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in after commit 742b8ed.

  • CVE-2011-0467HigJun 7, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE Studio Onsite: versions prior to 1.0.3-0.18.1, SUSE Studio…

  • CVE-2018-1252HigJun 5, 2018
    risk 0.57cvss 8.8epss 0.02

    RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end…

  • CVE-2016-10554CriMay 31, 2018
    risk 0.57cvss 9.8epss 0.02

    sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping, even though SQLite…

  • CVE-2016-10551CriMay 29, 2018
    risk 0.57cvss 9.8epss 0.02

    waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their…

  • CVE-2018-11470HigMay 25, 2018
    risk 0.57cvss 8.8epss 0.01

    iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.

  • CVE-2018-11414HigMay 24, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly.

  • CVE-2018-10352HigMay 23, 2018
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formConfiguration class. Authentication is required to exploit this vulnerability.

  • CVE-2018-10351HigMay 23, 2018
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRegistration2 class. Authentication is required to exploit this vulnerability.

  • CVE-2018-9019CriMay 22, 2018
    risk 0.57cvss 9.8epss 0.04

    SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php,…