VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 56 of 1,041
  • CVE-2024-52057CriDec 13, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allows SQL Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0, from 6.1.0 before 6.1.2.17, from 6.0.0 before…

  • CVE-2024-11837CriDec 13, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac  allows N1QL Injection.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-54811CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.

  • CVE-2024-54810CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.

  • CVE-2024-55099CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

  • CVE-2024-54842CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.

  • CVE-2024-53480CriDec 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

  • CVE-2024-54934CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.

  • CVE-2024-54932CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

  • CVE-2024-54931CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

  • CVE-2024-54925CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

  • CVE-2024-54924CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.

  • CVE-2024-54923CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.

  • CVE-2024-54921CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.

  • CVE-2022-38947CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.

  • CVE-2024-54920CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.

  • CVE-2024-8259CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection. This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. …

  • CVE-2024-50389CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: QuRouter 2.4.5.032 and later

  • CVE-2024-52335CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to…

  • CVE-2024-53908CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications…