VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 399 of 1,044
  • CVE-2021-24651HigOct 11, 2021
    risk 0.49cvss 7.5epss 0.02

    The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.

  • CVE-2021-41920HigOct 8, 2021
    risk 0.49cvss 7.5epss 0.02

    webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the…

  • CVE-2021-41651HigOct 4, 2021
    risk 0.49cvss 7.5epss 0.02

    A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive database information and interact with the database using the vulnerable cid parameter in process_update_profile.php.

  • CVE-2020-20340HigSep 1, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.

  • CVE-2020-18913HigAug 24, 2021
    risk 0.49cvss 7.5epss 0.01

    EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.

  • CVE-2020-18877HigAug 20, 2021
    risk 0.49cvss 7.5epss 0.01

    SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.

  • CVE-2020-22122HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.

  • CVE-2020-20981HigAug 12, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.

  • CVE-2020-23150HigAug 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php.

  • CVE-2020-23149HigAug 9, 2021
    risk 0.49cvss 7.5epss 0.01

    The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information.

  • CVE-2020-28087HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.

  • CVE-2021-25201HigJul 23, 2021
    risk 0.49cvss 7.5epss 0.02

    SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.

  • CVE-2020-23282HigJul 21, 2021
    risk 0.49cvss 7.5epss 0.01

    SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information.

  • CVE-2020-29147HigJul 14, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitive database information.

  • CVE-2020-20585HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.02

    A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.

  • CVE-2020-20583HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in /question.php of LJCMS Version v4.3.R60321 allows attackers to obtain sensitive database information.

  • CVE-2021-28993HigJun 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Plixer Scrutinizer 19.0.2 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).

  • CVE-2020-22175HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22174HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22173HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.