VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 61 of 1,041
  • CVE-2024-43773CriSep 2, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.

  • CVE-2024-43772CriSep 2, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.

  • CVE-2024-41372CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.

  • CVE-2024-41370CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.

  • CVE-2024-29731CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/…

  • CVE-2024-29730CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ ,…

  • CVE-2024-29729CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/,…

  • CVE-2024-29728CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ ,…

  • CVE-2024-29727CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRe…

  • CVE-2024-29726CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/,…

  • CVE-2024-29725CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/,…

  • CVE-2024-29724CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter…

  • CVE-2024-29723CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/,…

  • CVE-2024-44761CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.

  • CVE-2024-7071CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection. This issue affects Brain Low-Code: before 2.1.0.

  • CVE-2024-45265CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

  • CVE-2024-42913CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.

  • CVE-2024-41444CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.

  • CVE-2024-8161CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information…

  • CVE-2024-42765CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters.