VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,418)

page 759 of 1,021
  • CVE-2024-7651MedAug 21, 2024
    risk 0.29cvss 5.6epss 0.00

    The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injection via the ‘app-builder-search’ parameter in all versions up to, and including, 4.2.6 due to insufficient escaping on the user supplied parameter and…

  • CVE-2024-29174MedJun 26, 2024
    risk 0.29cvss 4.4epss 0.00

    Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database…

  • CVE-2024-3060MedApr 26, 2024
    risk 0.29cvss 4.5epss 0.01

    The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks

  • CVE-2022-4963MedMar 21, 2024
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function dropSchema of the file tenant/src/main/java/org/folio/spring/tenant/hibernate/HibernateSchemaService.java of the component Schema Name…

  • CVE-2024-22221MedFeb 12, 2024
    risk 0.29cvss 4.5epss 0.00

    Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information.

  • CVE-2018-25088MedJul 18, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in Blue Yonder postgraas_server up to 2.0.0b2. Affected is the function _create_pg_connection/create_postgres_db of the file postgraas_server/backends/postgres_cluster/postgres_cluster_driver.py of the component…

  • CVE-2016-15034MedJul 10, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in Dynacase Webdesk and classified as critical. Affected by this issue is the function freedomrss_search of the file freedomrss_search.php. The manipulation leads to sql injection. Upgrading to version 3.2-20180305 is able to address this issue. The…

  • CVE-2023-30944MedMay 2, 2023
    risk 0.29cvss 5.6epss 0.01

    The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the…

  • CVE-2015-10084MedFeb 21, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in irontec klear-library chloe and classified as critical. Affected by this issue is the function _prepareWhere of the file Controller/Rest/BaseController.php. The manipulation leads to sql injection. Upgrading to version marla is able to address this…

  • CVE-2015-10076MedFeb 9, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in dimtion Shaarlier up to 1.2.2. It has been declared as critical. Affected by this vulnerability is the function createTag of the file app/src/main/java/com/dimtion/shaarlier/TagsSource.java of the component Tag Handler. The manipulation leads to sql…

  • CVE-2011-10003MedFeb 7, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in XpressEngine up to 1.4.4. It has been rated as critical. This issue affects some unknown processing of the component Update Query Handler. The manipulation leads to sql injection. Upgrading to version 1.4.5 is able to address this issue. The patch is…

  • CVE-2011-10002MedFeb 7, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in weblabyrinth 0.3.1. This affects the function Labyrinth of the file labyrinth.inc.php. The manipulation leads to sql injection. Upgrading to version 0.3.2 is able to address this issue. The identifier of the patch is…

  • CVE-2014-125086MedFeb 6, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability has been found in Gimmie Plugin 1.2.2 on vBulletin and classified as critical. Affected by this vulnerability is an unknown functionality of the file trigger_login.php. The manipulation of the argument userid leads to sql injection. Upgrading to version 1.3.0 is…

  • CVE-2014-125085MedFeb 6, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in Gimmie Plugin 1.2.2 on vBulletin. Affected is an unknown function of the file trigger_ratethread.php. The manipulation of the argument t/postusername leads to sql injection. Upgrading to version 1.3.0 is able to…

  • CVE-2014-125084MedFeb 6, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, has been found in Gimmie Plugin 1.2.2 on vBulletin. This issue affects some unknown processing of the file trigger_referral.php. The manipulation of the argument referrername leads to sql injection. Upgrading to version 1.3.0 is…

  • CVE-2013-10018MedFeb 4, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in fanzila WebFinance 0.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file htdocs/prospection/save_contact.php. The manipulation of the argument nom/prenom/email/tel/mobile/client/fonction/note…

  • CVE-2013-10017MedFeb 4, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in fanzila WebFinance 0.5. It has been classified as critical. Affected is an unknown function of the file htdocs/admin/save_roles.php. The manipulation of the argument id leads to sql injection. The name of the patch is…

  • CVE-2013-10016MedFeb 3, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in fanzila WebFinance 0.5 and classified as critical. This issue affects some unknown processing of the file htdocs/admin/save_taxes.php. The manipulation of the argument id leads to sql injection. The patch is named…

  • CVE-2013-10015MedFeb 3, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability has been found in fanzila WebFinance 0.5 and classified as critical. This vulnerability affects unknown code of the file htdocs/admin/save_Contract_Signer_Role.php. The manipulation of the argument n/v leads to sql injection. The patch is identified as…

  • CVE-2014-125083MedJan 19, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability has been found in Anant Labs google-enterprise-connector-dctm up to 3.2.3 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/domain leads to sql injection. The patch is named…