VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 398 of 1,044
  • CVE-2021-38694HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.

  • CVE-2021-39978HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy and security issues.

  • CVE-2021-44600HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was…

  • CVE-2021-44599HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. A crafted payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The…

  • CVE-2020-18081HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.

  • CVE-2021-36299HigNov 23, 2021
    risk 0.49cvss 7.1epss 0.30

    Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by…

  • CVE-2021-28022HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.

  • CVE-2020-18263HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.01

    PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.

  • CVE-2020-28702HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.

  • CVE-2021-25874HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

  • CVE-2021-41746HigOct 29, 2021
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information.

  • CVE-2021-37807HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.02

    An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.

  • CVE-2021-26609HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information.

  • CVE-2020-19961HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.

  • CVE-2020-19960HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.

  • CVE-2020-19959HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.

  • CVE-2020-19957HigOct 14, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.

  • CVE-2021-33734HigOct 12, 2021
    risk 0.49cvss 7.2epss 0.28

    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

  • CVE-2021-33732HigOct 12, 2021
    risk 0.49cvss 7.2epss 0.28

    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.

  • CVE-2021-33730HigOct 12, 2021
    risk 0.49cvss 7.2epss 0.28

    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker could execute arbitrary commands in the local database by sending crafted requests to the webserver of the affected application.