VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 73 of 1,043
  • CVE-2024-29876CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

  • CVE-2024-29875CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/default/reports/exportactiveuserrpt, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data…

  • CVE-2024-29874CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/default/reports/activeuserrptpdf, 'sort_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from…

  • CVE-2024-29873CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from…

  • CVE-2024-29872CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/empscreening/add, 'agencyids' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.

  • CVE-2024-29871CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/sentrifugo/index.php/index/updatecontactnumber, 'id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and…

  • CVE-2024-29870CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote…

  • CVE-2024-29732CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.

  • CVE-2023-48901CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

  • CVE-2024-25239CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.

  • CVE-2024-28395CriMar 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.

  • CVE-2024-28392CriMar 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.

  • CVE-2024-1711CriMar 20, 2024
    risk 0.64cvss 9.8epss 0.01

    The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2024-28389CriMar 19, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.

  • CVE-2024-28303CriMar 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.

  • CVE-2024-25227CriMar 15, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.

  • CVE-2024-28388CriMar 14, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the StProductCommentClass::getListcomments method.

  • CVE-2024-25250CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

  • CVE-2024-24101CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.00

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

  • CVE-2024-24093CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.