VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 393 of 1,044
  • CVE-2023-31607HigMay 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the __libc_malloc component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

  • CVE-2023-30243HigMay 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.

  • CVE-2023-30112HigApr 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.

  • CVE-2023-27649HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table

  • CVE-2023-29626HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php.

  • CVE-2022-46021HigMar 31, 2023
    risk 0.49cvss 7.5epss 0.01

    X-Man 1.0 has a SQL injection vulnerability, which can cause data leakage.

  • CVE-2023-27871HigMar 21, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613.

  • CVE-2021-34249HigFeb 24, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.

  • CVE-2021-32441HigFeb 17, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.

  • CVE-2021-38239HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.

  • CVE-2021-34117HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.

  • CVE-2023-24647HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.

  • CVE-2021-37316HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.

  • CVE-2021-36432HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php.

  • CVE-2023-0324HigJan 16, 2023
    risk 0.49cvss 7.3epss 0.19

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack…

  • CVE-2022-40049HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page.

  • CVE-2022-45041HigDec 19, 2022
    risk 0.49cvss 7.5epss 0.01

    SQL Injection exits in xinhu < 2.5.0

  • CVE-2022-44790HigDec 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.

  • CVE-2022-45019HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.

  • CVE-2022-45329HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.