VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 404 of 1,044
  • CVE-2019-13191HigSep 5, 2019
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page.

  • CVE-2019-14937HigAug 17, 2019
    risk 0.49cvss 7.5epss 0.01

    REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to…

  • CVE-2017-18406HigAug 2, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).

  • CVE-2019-12946HigJul 19, 2019
    risk 0.49cvss 7.5epss 0.01

    Elcom CMS before 10.7 has SQL Injection via EventSearchByState.aspx and EventSearchAdv.aspx.

  • CVE-2017-11559HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.

  • CVE-2019-11880HigMay 22, 2019
    risk 0.49cvss 7.5epss 0.02

    CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2.

  • CVE-2018-17048HigMay 16, 2019
    risk 0.49cvss 7.5epss 0.02

    admin/Lib/Action/FpluginAction.class.php in FDCMS (aka Fangfa Content Manage System) 4.2 allows SQL Injection.

  • CVE-2017-12761HigMay 9, 2019
    risk 0.49cvss 7.5epss 0.03

    http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explore…

  • CVE-2019-11614HigApr 30, 2019
    risk 0.49cvss 7.5epss 0.02

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information.

  • CVE-2018-20505HigApr 3, 2019
    risk 0.49cvss 7.5epss 0.07

    SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).

  • CVE-2018-20730HigJan 17, 2019
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.

  • CVE-2019-5488HigJan 7, 2019
    risk 0.49cvss 7.5epss 0.01

    EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database.

  • CVE-2019-3494HigJan 1, 2019
    risk 0.49cvss 7.5epss 0.01

    Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.

  • CVE-2018-1000890HigDec 28, 2018
    risk 0.49cvss 7.5epss 0.02

    FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.

  • CVE-2018-20061HigDec 11, 2018
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a…

  • CVE-2018-20018HigDec 10, 2018
    risk 0.49cvss 7.5epss 0.01

    S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.

  • CVE-2018-19331HigNov 17, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.

  • CVE-2018-0404HigOct 5, 2018
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker could retrieve…

  • CVE-2018-17562HigOct 3, 2018
    risk 0.49cvss 7.5epss 0.01

    Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.

  • CVE-2018-16384HigSep 3, 2018
    risk 0.49cvss 7.5epss 0.02

    A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.