VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 317 of 1,043
  • CVE-2024-36485HigNov 4, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

  • CVE-2024-48878HigNov 4, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

  • CVE-2024-5608HigOct 24, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.

  • CVE-2024-6204HigAug 30, 2024
    risk 0.54cvss 8.3epss 0.02

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

  • CVE-2024-5546HigAug 28, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.

  • CVE-2024-5586HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.

  • CVE-2024-5556HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.

  • CVE-2024-5490HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

  • CVE-2024-5467HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

  • CVE-2024-36517HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

  • CVE-2024-36516HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.

  • CVE-2024-36515HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.

  • CVE-2024-36514HigAug 23, 2024
    risk 0.54cvss 8.3epss 0.04

    Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

  • CVE-2024-5725HigAug 21, 2024
    risk 0.54cvss 8.8epss 0.47

    Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-5527HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

  • CVE-2024-5487HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

  • CVE-2024-36518HigAug 12, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

  • CVE-2024-38872HigJul 26, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

  • CVE-2024-38871HigJul 26, 2024
    risk 0.54cvss 8.3epss 0.03

    Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

  • CVE-2024-37148HigJul 10, 2024
    risk 0.54cvss 8.1epss 0.20

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can exploit a SQL injection vulnerability in some AJAX scripts to alter another user account data and take…