VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (8,797)

page 5 of 440
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-17629Cri0.679.80.03Dec 13, 2017Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.
CVE-2017-17628Cri0.679.80.03Dec 13, 2017Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
CVE-2017-17627Cri0.679.80.03Dec 13, 2017Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
CVE-2017-17626Cri0.679.80.03Dec 13, 2017Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
CVE-2017-17625Cri0.679.80.02Dec 13, 2017Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
CVE-2017-17624Cri0.679.80.03Dec 13, 2017PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
CVE-2017-17623Cri0.679.80.03Dec 13, 2017Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
CVE-2017-17622Cri0.679.80.04Dec 13, 2017Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
CVE-2017-17621Cri0.679.80.04Dec 13, 2017Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
CVE-2017-17620Cri0.679.80.03Dec 13, 2017Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
CVE-2017-17619Cri0.679.80.04Dec 13, 2017Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17618Cri0.679.80.03Dec 13, 2017Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
CVE-2017-17617Cri0.679.80.03Dec 13, 2017Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
CVE-2017-17616Cri0.679.80.03Dec 13, 2017Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
CVE-2017-17614Cri0.679.80.03Dec 13, 2017Food Order Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17613Cri0.679.80.03Dec 13, 2017Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.
CVE-2017-17612Cri0.679.80.04Dec 13, 2017Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
CVE-2017-17611Cri0.679.80.03Dec 13, 2017Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
CVE-2017-17610Cri0.679.80.03Dec 13, 2017E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
CVE-2017-17609Cri0.679.80.03Dec 13, 2017Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.