VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (12,807)

page 564 of 641
  • CVE-2007-6084Nov 22, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-6091Nov 22, 2007
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password…

  • CVE-2007-6078Nov 21, 2007
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) nc_top.asp; (2) inc_bookmarks.asp, possibly involving a parameter passed from cp_main.asp; (3) inc_profile_functions.asp; or (4)…

  • CVE-2007-6080Nov 21, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. NOTE: it was later reported that 1.0.13 is also affected.

  • CVE-2007-6058Nov 20, 2007
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in…

  • CVE-2007-6032Nov 20, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in calendar/page.asp in Aleris Web Publishing Server 3.0 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

  • CVE-2007-5997Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-5992Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page.

  • CVE-2007-6004Nov 15, 2007
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an artikel action or (2) the katid parameter in a produk action.

  • CVE-2007-5999Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-5998Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.

  • CVE-2007-5996Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449.

  • CVE-2007-5978Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.

  • CVE-2007-5974Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.

  • CVE-2007-5973Nov 15, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.

  • CVE-2007-5951Nov 14, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in articles.php in E-Vendejo 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-5912Nov 10, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.

  • CVE-2007-5887Nov 7, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-4863Oct 30, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter.

  • CVE-2007-5719Oct 30, 2007
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php.