VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 400 of 1,044
  • CVE-2020-22172HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22171HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22170HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22169HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22168HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22166HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22165HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.06

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22164HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-20474HigJun 21, 2021
    risk 0.49cvss 7.5epss 0.02

    White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-20473HigJun 21, 2021
    risk 0.49cvss 7.5epss 0.02

    White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive…

  • CVE-2020-20469HigJun 21, 2021
    risk 0.49cvss 7.5epss 0.02

    White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain database sensitive information.

  • CVE-2021-32582HigJun 17, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that can enable an attacker to extract database information or administrative credentials from an instance via crafted monitor status…

  • CVE-2021-32932HigJun 11, 2021
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).

  • CVE-2020-25362HigJun 2, 2021
    risk 0.49cvss 7.5epss 0.02

    The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.

  • CVE-2020-24862HigJun 2, 2021
    risk 0.49cvss 7.5epss 0.02

    The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.

  • CVE-2021-24295HigMay 17, 2021
    risk 0.49cvss 7.5epss 0.05

    It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that…

  • CVE-2021-32051HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.02

    Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter.

  • CVE-2020-22781HigApr 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).

  • CVE-2020-18019HigApr 28, 2021
    risk 0.49cvss 7.5epss 0.02

    SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.

  • CVE-2021-28828HigApr 20, 2021
    risk 0.49cvss 7.6epss 0.01

    The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for…