VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 535 of 1,044
  • CVE-2023-41443HigSep 18, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.

  • CVE-2023-21521HigSep 12, 2023
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on…

  • CVE-2023-2188HigAug 31, 2023
    risk 0.47cvss 7.2epss 0.01

    The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2023-31945HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php.

  • CVE-2023-31944HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php.

  • CVE-2023-31943HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php.

  • CVE-2023-31940HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php.

  • CVE-2023-31939HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php.

  • CVE-2023-31938HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php.

  • CVE-2023-3864HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.01

    Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

  • CVE-2023-37687HigAug 8, 2023
    risk 0.47cvss 7.2epss 0.01

    Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.

  • CVE-2023-4184HigAug 6, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2023-4182HigAug 6, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2023-39121HigAug 3, 2023
    risk 0.47cvss 7.2epss 0.03

    emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

  • CVE-2023-21412HigAug 3, 2023
    risk 0.47cvss 7.2epss 0.01

    User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.

  • CVE-2023-31937HigJul 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file.

  • CVE-2023-31936HigJul 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file.

  • CVE-2023-31933HigJul 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file.

  • CVE-2023-31932HigJul 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file.

  • CVE-2023-36968HigJul 6, 2023
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.