VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 536 of 1,044
  • CVE-2023-2592HigJun 27, 2023
    risk 0.47cvss 7.2epss 0.01

    The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

  • CVE-2023-2482HigJun 27, 2023
    risk 0.47cvss 7.2epss 0.01

    The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.

  • CVE-2020-21400HigJun 20, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.

  • CVE-2020-20491HigJun 20, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.

  • CVE-2023-2607HigJun 9, 2023
    risk 0.47cvss 7.2epss 0.01

    The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2023-2484HigJun 9, 2023
    risk 0.47cvss 7.2epss 0.01

    The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2022-24628HigMay 29, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php.

  • CVE-2023-33439HigMay 26, 2023
    risk 0.47cvss 7.2epss 0.03

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.

  • CVE-2023-31845HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.

  • CVE-2023-31844HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.

  • CVE-2023-31843HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.

  • CVE-2023-31842HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.

  • CVE-2023-32569HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The InfoScale VIOM web application is vulnerable to SQL Injection in some of the areas of the application. This allows attackers (who must have admin credentials) to…

  • CVE-2023-2519HigMay 4, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Caton CTP Relay Server 1.2.9 and classified as critical. This vulnerability affects unknown code of the file /server/api/v1/login of the component API. The manipulation of the argument username/password leads to sql injection. The attack can be…

  • CVE-2023-27733HigApr 17, 2023
    risk 0.47cvss 7.2epss 0.01

    DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.

  • CVE-2023-26856HigApr 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login.

  • CVE-2023-1737HigMar 30, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to initiate the attack…

  • CVE-2023-24840HigMar 27, 2023
    risk 0.47cvss 7.2epss 0.01

    HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.

  • CVE-2023-27709HigMar 16, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.

  • CVE-2023-27707HigMar 16, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.