VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 69 of 1,043
  • CVE-2024-4991CriMay 16, 2024
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.

  • CVE-2024-4826CriMay 16, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id…

  • CVE-2024-34955CriMay 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.

  • CVE-2024-4893CriMay 15, 2024
    risk 0.64cvss 9.8epss 0.01

    DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.

  • CVE-2024-33485CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component

  • CVE-2024-34256CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

  • CVE-2024-4824CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL…

  • CVE-2024-25532CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.

  • CVE-2024-31961CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbitrary SQL commands via the level2 parameter.

  • CVE-2024-25531CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.

  • CVE-2024-25530CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.

  • CVE-2024-25529CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.

  • CVE-2024-25525CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.

  • CVE-2024-25523CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.

  • CVE-2024-25520CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.

  • CVE-2024-25519CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.

  • CVE-2024-25517CriMay 8, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.

  • CVE-2024-25510CriMay 7, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aspx.

  • CVE-2024-25508CriMay 7, 2024
    risk 0.64cvss 9.8epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx.

  • CVE-2024-33164CriMay 7, 2024
    risk 0.64cvss 9.8epss 0.01

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.