VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 395 of 1,044
  • CVE-2022-36394HigAug 23, 2022
    risk 0.49cvss 7.6epss 0.01

    Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.

  • CVE-2022-34968HigAug 3, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service (DoS) via a SQL query.

  • CVE-2022-34067HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.

  • CVE-2022-29709HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the username and password parameters.

  • CVE-2022-32297HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.

  • CVE-2022-32055HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=search/rentals.

  • CVE-2021-41460HigJun 28, 2022
    risk 0.49cvss 7.5epss 0.07

    ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.

  • CVE-2022-33097HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.

  • CVE-2022-33096HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.

  • CVE-2022-33095HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

  • CVE-2022-33094HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.

  • CVE-2022-33093HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.

  • CVE-2022-33092HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.

  • CVE-2021-40956HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

  • CVE-2017-20029HigJun 10, 2022
    risk 0.49cvss 7.3epss 0.21

    A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2022-30496HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.

  • CVE-2021-26633HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulating a variable with a desired value and inserting and arbitrary file.

  • CVE-2022-29721HigMay 26, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

  • CVE-2022-31489HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.

  • CVE-2022-31488HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.