VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 743 of 1,022
  • CVE-2021-21921MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21920MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘surname_filter’ parameter with the administrative account or through cross-site request forgery.

  • CVE-2021-21919MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ord’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site…

  • CVE-2021-21918MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without…

  • CVE-2021-40129MedNov 19, 2021
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input validation of uploaded…

  • CVE-2021-27999MedAug 19, 2021
    risk 0.32cvss 4.9epss 0.01

    A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the database.

  • CVE-2021-32790MedJul 26, 2021
    risk 0.32cvss 4.9epss 0.01

    Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sites running the WooCommerce plugin between version 3.3.0 and 3.3.6. Malicious actors (already) having admin access, or API keys to the WooCommerce site can…

  • CVE-2020-10983MedJul 28, 2020
    risk 0.32cvss 4.9epss 0.01

    Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php.

  • CVE-2020-10982MedJul 28, 2020
    risk 0.32cvss 4.9epss 0.01

    Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php.

  • CVE-2020-5768MedJul 17, 2020
    risk 0.32cvss 4.9epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.

  • CVE-2020-3450MedJul 16, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative credentials to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of…

  • CVE-2020-3154MedFeb 19, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticated attacker could…

  • CVE-2019-17271MedOct 8, 2019
    risk 0.32cvss 4.9epss 0.01

    vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.

  • CVE-2019-12710MedOct 2, 2019
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an authenticated, remote attacker to impact the confidentiality of an affected system by executing arbitrary…

  • CVE-2019-11625MedApr 30, 2019
    risk 0.32cvss 4.9epss 0.01

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php. A remote background administrator privilege user (or a user with permission to manage emailing) could exploit the vulnerability to obtain database sensitive information.

  • CVE-2019-11623MedApr 30, 2019
    risk 0.32cvss 4.9epss 0.01

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=siteweb. A remote background administrator privilege user (or a user with permission to manage configuration siteweb) could exploit the vulnerability to obtain…

  • CVE-2019-11622MedApr 30, 2019
    risk 0.32cvss 4.9epss 0.01

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information…

  • CVE-2019-11621MedApr 30, 2019
    risk 0.32cvss 4.9epss 0.01

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=network. A remote background administrator privilege user (or a user with permission to manage network configuration) could exploit the vulnerability to obtain…

  • CVE-2019-11620MedApr 30, 2019
    risk 0.32cvss 4.9epss 0.01

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote background administrator privilege user (or a user with permission to manage modulecategory) could exploit the vulnerability to obtain database sensitive information…

  • CVE-2019-11619MedApr 30, 2019
    risk 0.32cvss 4.9epss 0.01

    doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analytics. A remote background administrator privilege user (or a user with permission to manage configuration analytics) could exploit the vulnerability to obtain…