VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 401 of 1,044
  • CVE-2021-28245HigMar 31, 2021
    risk 0.49cvss 7.5epss 0.01

    PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.

  • CVE-2021-27320HigMar 24, 2021
    risk 0.49cvss 7.5epss 0.09

    Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.

  • CVE-2021-27319HigMar 24, 2021
    risk 0.49cvss 7.5epss 0.08

    Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.

  • CVE-2021-27316HigMar 24, 2021
    risk 0.49cvss 7.5epss 0.08

    Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.

  • CVE-2021-27315HigMar 24, 2021
    risk 0.49cvss 7.5epss 0.08

    Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.

  • CVE-2021-26578HigMar 22, 2021
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.

  • CVE-2021-26935HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.02

    In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.

  • CVE-2021-23352HigMar 9, 2021
    risk 0.49cvss 8.6epss 0.02

    This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.

  • CVE-2020-36003HigFeb 17, 2021
    risk 0.49cvss 7.5epss 0.02

    The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.

  • CVE-2020-36002HigFeb 17, 2021
    risk 0.49cvss 7.5epss 0.02

    Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.

  • CVE-2021-22854HigFeb 17, 2021
    risk 0.49cvss 7.5epss 0.02

    The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege.

  • CVE-2020-29228HigDec 30, 2020
    risk 0.49cvss 7.5epss 0.01

    EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.

  • CVE-2020-35122HigDec 15, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could bypass the access controls for using a saved database connection profile to submit arbitrary SQL against a saved database connection.

  • CVE-2018-19952HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.01

    If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.

  • CVE-2020-23945HigOct 27, 2020
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.

  • CVE-2020-25157HigOct 20, 2020
    risk 0.49cvss 7.5epss 0.01

    The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.

  • CVE-2020-9417HigOct 20, 2020
    risk 0.49cvss 7.6epss 0.01

    The Transaction Insight reporting component of TIBCO Software Inc.'s TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO…

  • CVE-2020-26546HigOct 12, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2020-19455HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via components/com_jdownloads/helpers/categories.php, order function via the filter_order parameter.

  • CVE-2020-19451HigSep 25, 2020
    risk 0.49cvss 7.5epss 0.01

    SQL injection exists in the jdownloads 3.2.63 component for Joomla! via com_jdownloads/helpers/jdownloadshelper.php, updateLog function via the X-forwarded-for Header parameter.