VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 396 of 1,044
  • CVE-2022-31487HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.

  • CVE-2022-30012HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.02

    In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.

  • CVE-2021-43010HigMay 10, 2022
    risk 0.49cvss 7.5epss 0.01

    In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensitive data.

  • CVE-2021-41942HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.01

    The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.

  • CVE-2022-28060HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.02

    SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.

  • CVE-2022-27386HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.

  • CVE-2022-27385HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27384HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27381HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27380HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27379HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27378HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27041HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.

  • CVE-2021-32957HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the…

  • CVE-2021-43109HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.

  • CVE-2021-44581HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.

  • CVE-2021-44345HigMar 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.

  • CVE-2021-45794HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.

  • CVE-2021-45793HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.05

    Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.

  • CVE-2022-25491HigMar 15, 2022
    risk 0.49cvss 7.5epss 0.01

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.