VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 68 of 1,043
  • CVE-2024-33806CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33805CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33801CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33800CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.

  • CVE-2024-33799CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-35091CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.00

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.

  • CVE-2024-35086CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .

  • CVE-2024-35084CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.00

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.

  • CVE-2024-34935CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.

  • CVE-2024-34934CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.

  • CVE-2024-34932CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.

  • CVE-2024-34931CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.

  • CVE-2024-34929CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index parameter.

  • CVE-2024-34927CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.

  • CVE-2023-51637CriMay 22, 2024
    risk 0.64cvss 9.8epss 0.01

    Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG. Authentication is not required to exploit this vulnerability. The…

  • CVE-2024-35409CriMay 22, 2024
    risk 0.64cvss 9.8epss 0.01

    WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

  • CVE-2024-35056CriMay 21, 2024
    risk 0.64cvss 9.8epss 0.01

    NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.

  • CVE-2024-35361CriMay 21, 2024
    risk 0.64cvss 9.8epss 0.01

    MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.

  • CVE-2024-4609CriMay 16, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack…

  • CVE-2024-4992CriMay 16, 2024
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.