VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 391 of 1,044
  • CVE-2023-25838HigJul 19, 2023
    risk 0.49cvss 7.5epss 0.01

    There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit…

  • CVE-2023-3743HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Ap Page Builder, in versions lower than 1.7.8.2, could allow a remote attacker to send a specially crafted SQL query to the product_one_img parameter to retrieve the information stored in the database.

  • CVE-2023-2760HigJul 17, 2023
    risk 0.49cvss 7.6epss 0.00

    An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access.…

  • CVE-2023-36293HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in wmanager v.1.0.7 and before allows a remote attacker to obtain sensitive information via a crafted script to the company.php component.

  • CVE-2023-29095HigJul 10, 2023
    risk 0.49cvss 7.6epss 0.01

    Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions.

  • CVE-2023-30325HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in textMessage parameter in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine v.1.0, allows attackers to gain sensitive information.

  • CVE-2023-30323HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to gain sensitive information.

  • CVE-2023-36284HigJun 23, 2023
    risk 0.49cvss 7.5epss 0.03

    An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

  • CVE-2022-47614HigJun 23, 2023
    risk 0.49cvss 7.5epss 0.01

    Unauth. SQL Injection (SQLi) vulnerability in InspireUI MStore API plugin <= 3.9.7 versions.

  • CVE-2023-36364HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the rel_deps component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36363HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the __nss_database_lookup component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-36362HigJun 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the rel_sequences component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2020-21486HigJun 20, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.

  • CVE-2020-20636HigJun 20, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.

  • CVE-2023-34603HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.01

    JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.

  • CVE-2021-31233HigMay 31, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability found in Fighting Cock Information System v.1.0 allows a remote attacker to obtain sensitive information via the edit_breed.php parameter.

  • CVE-2023-31631HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlo_preds_contradiction component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-31630HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlo_query_spec component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-31629HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the sqlo_union_scope component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-31628HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the stricmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.