VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 31 of 1,041
  • CVE-2021-40850CriDec 17, 2021
    risk 0.65cvss 10.0epss 0.01

    TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.

  • CVE-2021-42313CriDec 15, 2021
    risk 0.65cvss 10.0epss 0.04

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2021-42311CriDec 15, 2021
    risk 0.65cvss 10.0epss 0.04

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2021-24915CriNov 29, 2021
    risk 0.65cvss 9.8epss 0.13

    The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform…

  • CVE-2021-3958CriNov 16, 2021
    risk 0.65cvss 9.8epss 0.14

    Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Injection.This issue affects Ipack SCADA Software: from unspecified before 1.1.0.

  • CVE-2021-24827CriNov 8, 2021
    risk 0.65cvss 9.8epss 0.13

    The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue

  • CVE-2021-42667CriNov 5, 2021
    risk 0.65cvss 9.8epss 0.16

    A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web…

  • CVE-2021-38393CriAug 30, 2021
    risk 0.65cvss 9.8epss 0.18

    A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter agid before using it as…

  • CVE-2021-38390CriAug 30, 2021
    risk 0.65cvss 9.8epss 0.20

    A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter egyid before using it as…

  • CVE-2021-24507CriAug 9, 2021
    risk 0.65cvss 9.8epss 0.11

    The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL…

  • CVE-2021-35049CriJun 25, 2021
    risk 0.65cvss 9.9epss 0.05

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an…

  • CVE-2021-31316CriMay 18, 2021
    risk 0.65cvss 9.8epss 0.13

    The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.

  • CVE-2021-24285CriMay 14, 2021
    risk 0.65cvss 9.8epss 0.15

    The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading…

  • CVE-2021-32099CriMay 7, 2021
    risk 0.65cvss 9.8epss 0.13

    A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass.

  • CVE-2021-27314CriMar 5, 2021
    risk 0.65cvss 9.8epss 0.12

    SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.

  • CVE-2021-3239CriFeb 15, 2021
    risk 0.65cvss 9.8epss 0.18

    E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell.

  • CVE-2021-22658CriFeb 11, 2021
    risk 0.65cvss 9.8epss 0.13

    Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalate privileges to 'Administrator'.

  • CVE-2021-3110CriJan 20, 2021
    risk 0.65cvss 9.8epss 0.19

    The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.

  • CVE-2020-29493CriJan 14, 2021
    risk 0.65cvss 10.0epss 0.03

    DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database,…

  • CVE-2021-21465CriJan 12, 2021
    risk 0.65cvss 9.9epss 0.04

    The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute without properly sanitizing the untrusted data leading to SQL…