VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 390 of 1,044
  • CVE-2023-41594HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.

  • CVE-2023-40771HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

  • CVE-2023-41539HigAug 30, 2023
    risk 0.49cvss 7.5epss 0.01

    phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.

  • CVE-2023-33852HigAug 27, 2023
    risk 0.49cvss 7.6epss 0.01

    IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614.

  • CVE-2023-38839HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via theID parameter in the fulldelete.php component.

  • CVE-2023-38838HigAug 17, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component.

  • CVE-2020-36136HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail parameter in csz_model.php.

  • CVE-2023-39417HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.02

    IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension,…

  • CVE-2023-40254HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from…

  • CVE-2023-38773HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp1 and volopp2 parameters within the /QueryView.php.

  • CVE-2023-38771HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the volopp parameter within the /QueryView.php.

  • CVE-2023-38770HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryView.php.

  • CVE-2023-38769HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the searchstring and searchwhat parameters within the /QueryView.php.

  • CVE-2023-38768HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the PropertyID parameter within the /QueryView.php.

  • CVE-2023-38767HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the 'value' and 'custom' parameters within the /QueryView.php.

  • CVE-2023-38765HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the membermonth parameter within the /QueryView.php.

  • CVE-2023-38764HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the birthmonth and percls parameters within the /QueryView.php.

  • CVE-2023-38762HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the friendmonths parameter within the /QueryView.php.

  • CVE-2023-38760HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the role and gender parameters within the /QueryView.php component.

  • CVE-2023-26439HigAug 2, 2023
    risk 0.49cvss 7.6epss 0.00

    The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users…