VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 394 of 1,044
  • CVE-2022-45932HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

  • CVE-2022-45931HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used.

  • CVE-2022-45930HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface.

  • CVE-2022-45331HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.

  • CVE-2022-45330HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.

  • CVE-2022-40405HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.

  • CVE-2022-41892HigNov 11, 2022
    risk 0.49cvss 8.6epss 0.01

    Arches is a web platform for creating, managing, & visualizing geospatial data. Versions prior to 6.1.2, 6.2.1, and 7.1.2 are vulnerable to SQL Injection. With a carefully crafted web request, it's possible to execute certain unwanted sql statements against the database. This…

  • CVE-2022-40839HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data.

  • CVE-2022-43081HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Fast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php.

  • CVE-2022-42924HigOct 31, 2022
    risk 0.49cvss 7.6epss 0.00

    Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'dyn_filter' parameter in the…

  • CVE-2022-41680HigOct 31, 2022
    risk 0.49cvss 7.6epss 0.00

    Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'search[value] parameter in the…

  • CVE-2021-36898HigOct 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.

  • CVE-2022-28813HigSep 28, 2022
    risk 0.49cvss 7.5epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of an SQL-injection to gain access to a volatile temporary database with the current states of the device.

  • CVE-2022-36259HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "username", "password", etc.

  • CVE-2022-36258HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".

  • CVE-2022-36257HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "users", "pass", etc.

  • CVE-2022-36256HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode".

  • CVE-2022-36255HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "searchTxt".

  • CVE-2022-37185HigSep 6, 2022
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability exists in the school information query interface (repschoolproj.php) of the EMS 6.2 system of the Office of the Thai Basic Education Commission, which can lead to data leakage.

  • CVE-2022-36581HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.