VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 63 of 1,041
  • CVE-2024-42843CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.

  • CVE-2024-7732CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

  • CVE-2024-7731CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

  • CVE-2024-40486CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.

  • CVE-2024-40477CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "email" parameter.

  • CVE-2024-40472CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."

  • CVE-2024-41237CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

  • CVE-2024-34480CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.

  • CVE-2024-34479CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.

  • CVE-2024-33974CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in…

  • CVE-2024-33973CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance'…

  • CVE-2024-33972CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in…

  • CVE-2024-33971CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in…

  • CVE-2024-33970CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in…

  • CVE-2024-33969CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…

  • CVE-2024-33968CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and…

  • CVE-2024-33967CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in…

  • CVE-2024-33966CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'xtsearch' in…

  • CVE-2024-33965CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in…

  • CVE-2024-33964CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…