VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 527 of 1,044
  • CVE-2024-54928HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,

  • CVE-2024-54927HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.

  • CVE-2024-54933HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

  • CVE-2024-54930HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

  • CVE-2024-54922HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.

  • CVE-2024-54929HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.01

    KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

  • CVE-2024-12187HigDec 5, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /showbook.php. The manipulation of the argument q leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2024-45757HigDec 3, 2024
    risk 0.47cvss 7.2epss 0.00

    An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to authenticated users with high-privileged access.

  • CVE-2024-11817HigNov 26, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection.…

  • CVE-2024-45756HigNov 25, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to…

  • CVE-2024-9887HigNov 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2024-11241HigNov 15, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file reset.php. The manipulation of the argument e leads to sql injection. The attack can be launched remotely. The…

  • CVE-2024-50831HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-50830HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.

  • CVE-2024-50829HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.

  • CVE-2024-50828HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.

  • CVE-2024-50827HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

  • CVE-2024-50826HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.

  • CVE-2024-50825HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.

  • CVE-2024-50824HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.