VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (12,807)

page 574 of 641
  • CVE-2003-1504Dec 31, 2003
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.

  • CVE-2003-1435Dec 31, 2003
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.

  • CVE-2003-1244Dec 31, 2003
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.

  • CVE-2003-1520Dec 31, 2003
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.

  • CVE-2003-1532Dec 31, 2003
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.

  • CVE-2003-0377Jun 16, 2003
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.

  • CVE-2002-2304Dec 31, 2002
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.

  • CVE-2021-37556HigAug 3, 2021
    risk 0.02cvss 8.8epss 0.27

    A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/reporting/dashboard/csvExport/csv_HostGroupLogs.php start and end…

  • CVE-2020-6637CriAug 24, 2020
    risk 0.02cvss 9.8epss 0.20

    openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

  • CVE-2019-14529CriAug 2, 2019
    risk 0.02cvss 9.8epss 0.28

    OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.

  • CVE-2019-10232CriMar 27, 2019
    risk 0.02cvss 9.8epss 0.23

    Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.

  • CVE-2018-10094CriMay 22, 2018
    risk 0.02cvss 9.8epss 0.71

    SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.

  • CVE-2014-3828Oct 23, 2014
    risk 0.02cvss epss 0.73

    Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter…

  • CVE-2011-1610May 3, 2011
    risk 0.02cvss epss 0.25

    Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow…

  • CVE-2022-1883HigMay 25, 2022
    risk 0.01cvss 8.8epss 0.07

    SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.

  • CVE-2022-24124HigJan 29, 2022
    risk 0.01cvss 7.5epss 0.59

    The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.

  • CVE-2021-24666CriSep 27, 2021
    risk 0.01cvss 9.8epss 0.09

    The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for…

  • CVE-2021-34187CriJun 28, 2021
    risk 0.01cvss 9.8epss 0.16

    main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

  • CVE-2015-1605Feb 24, 2015
    risk 0.01cvss epss 0.18

    Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) GetClientPackage.aspx or (2) GetProcessedPackage.aspx.

  • CVE-2013-1617Aug 1, 2013
    risk 0.01cvss epss 0.07

    Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.