VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 71 of 1,043
  • CVE-2024-33275CriApr 30, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.

  • CVE-2024-33273CriApr 30, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in shipup before v.3.3.0 allows a remote attacker to escalate privileges via the getShopID function.

  • CVE-2024-33267CriApr 30, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayBackModuleFrontController::initContent() function.

  • CVE-2024-33276CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method.

  • CVE-2024-33269CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::getFlashSales method.

  • CVE-2024-33268CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addGiftToCart method.

  • CVE-2024-33266CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.

  • CVE-2024-33444CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.

  • CVE-2024-33559CriApr 29, 2024
    risk 0.64cvss 9.3epss 0.04

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.

  • CVE-2024-28322CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.

  • CVE-2024-28613CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.

  • CVE-2024-31546CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.

  • CVE-2024-30938CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.

  • CVE-2024-30922CriApr 18, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering.

  • CVE-2024-30990CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.

  • CVE-2024-30985CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

  • CVE-2024-30982CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

  • CVE-2024-30981CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL.

  • CVE-2024-30980CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.

  • CVE-2024-28557CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.