VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 731 of 1,022
  • CVE-2020-14207MedDec 8, 2020
    risk 0.35cvss 5.3epss 0.01

    The DiveBook plugin 1.1.4 for WordPress was prone to a SQL injection within divelog.php, allowing unauthenticated users to retrieve data from the database via the divelog.php filter_diver parameter.

  • CVE-2020-25700MedNov 19, 2020
    risk 0.35cvss 6.5epss 0.01

    In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

  • CVE-2020-17373MedAug 12, 2020
    risk 0.35cvss 5.3epss 0.01

    SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.

  • CVE-2020-15873MedJul 21, 2020
    risk 0.35cvss 6.5epss 0.02

    In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.

  • CVE-2020-3468MedJul 16, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates…

  • CVE-2019-14900MedJul 6, 2020
    risk 0.35cvss 6.5epss 0.02

    A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an…

  • CVE-2020-3339MedJun 3, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted parameters. An attacker…

  • CVE-2020-10381MedApr 14, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing attackers to discover database and table names.

  • CVE-2020-10803MedMar 22, 2020
    risk 0.35cvss 5.4epss 0.01

    In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker…

  • CVE-2019-8143MedNov 6, 2019
    risk 0.35cvss 6.5epss 0.01

    A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with access to email templates can send malicious SQL queries and obtain access to sensitive information stored in the database.

  • CVE-2018-17092MedSep 16, 2018
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be exploited via specially crafted input, allowing an attacker to obtain information from a database. The vulnerability can only be triggered by an authorized user.

  • CVE-2018-6494MedMay 22, 2018
    risk 0.35cvss 5.4epss 0.01

    Remote SQL Injection against the HP Service Manager Software Web Tier, version 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, may lead to unauthorized disclosure of data.

  • CVE-2018-5443MedJan 25, 2018
    risk 0.35cvss 5.3epss 0.01

    A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.

  • CVE-2017-0304MedDec 21, 2017
    risk 0.35cvss 5.4epss 0.01

    A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tampered with and impact the Configuration Utility until there is a resync of the rules. Traffic…

  • CVE-2017-16735MedDec 20, 2017
    risk 0.35cvss 5.3epss 0.01

    A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which generates an error in the database log.

  • CVE-2017-16733MedDec 20, 2017
    risk 0.35cvss 5.3epss 0.01

    A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.

  • CVE-2017-12227MedSep 7, 2017
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection…

  • CVE-2017-6698MedJul 4, 2017
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL…

  • CVE-2017-4974MedJun 13, 2017
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x…

  • CVE-2016-8929MedFeb 1, 2017
    risk 0.35cvss 5.4epss 0.01

    IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.