VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 397 of 1,044
  • CVE-2022-24601HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements.

  • CVE-2021-40636HigMar 3, 2022
    risk 0.49cvss 7.5epss 0.01

    OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.

  • CVE-2021-40635HigMar 3, 2022
    risk 0.49cvss 7.5epss 0.01

    OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.

  • CVE-2022-25393HigMar 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

  • CVE-2022-23387HigMar 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment Update field.

  • CVE-2022-23986HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.02

    SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the information in the database via unspecified vectors.

  • CVE-2022-24226HigFeb 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.

  • CVE-2022-24646HigFeb 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.

  • CVE-2022-22540HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of…

  • CVE-2021-44866HigFeb 3, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

  • CVE-2022-24121HigFeb 3, 2022
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.

  • CVE-2022-24266HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.06

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

  • CVE-2022-24265HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.07

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

  • CVE-2022-24264HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.07

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

  • CVE-2021-46459HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.

  • CVE-2021-46458HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.

  • CVE-2022-24124HigJan 29, 2022
    risk 0.49cvss 7.5epss 0.55

    The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.

  • CVE-2021-46385HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2021-46383HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2021-43863HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.02

    The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContentProvider` and `DiskLruImageCacheFileProvider` have security…