VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 742 of 1,022
  • CVE-2024-25288MedFeb 21, 2024
    risk 0.32cvss 4.9epss 0.01

    SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

  • CVE-2020-26630MedJan 10, 2024
    risk 0.32cvss 4.9epss 0.01

    A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.

  • CVE-2020-26627MedJan 10, 2024
    risk 0.32cvss 4.9epss 0.01

    A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.

  • CVE-2023-30867MedDec 15, 2023
    risk 0.32cvss 4.9epss 0.01

    In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName field may receive…

  • CVE-2023-46025MedNov 14, 2023
    risk 0.32cvss 4.9epss 0.01

    SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.

  • CVE-2023-5322MedOct 1, 2023
    risk 0.32cvss 4.7epss 0.17

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/edit_manageadmin.php. The manipulation of the argument id leads to sql…

  • CVE-2023-43493MedSep 27, 2023
    risk 0.32cvss 4.9epss 0.01

    SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.

  • CVE-2023-39582MedSep 1, 2023
    risk 0.32cvss 4.9epss 0.01

    SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.

  • CVE-2022-46047MedDec 13, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.

  • CVE-2022-45536MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.

  • CVE-2022-45535MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.

  • CVE-2022-45529MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.

  • CVE-2022-43709MedNov 22, 2022
    risk 0.32cvss 4.9epss 0.01

    MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.

  • CVE-2021-37823MedNov 3, 2022
    risk 0.32cvss 4.9epss 0.01

    OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.

  • CVE-2022-43086MedNov 1, 2022
    risk 0.32cvss 4.9epss 0.01

    Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.

  • CVE-2022-2137MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information

  • CVE-2022-1691MedJun 8, 2022
    risk 0.32cvss 4.9epss 0.01

    The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection

  • CVE-2022-1685MedJun 8, 2022
    risk 0.32cvss 4.9epss 0.01

    The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection

  • CVE-2020-19212MedMay 6, 2022
    risk 0.32cvss 4.9epss 0.01

    SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.

  • CVE-2021-21923MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery.