VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,387)

page 792 of 1,020
  • CVE-2011-5212Oct 22, 2012
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.

  • CVE-2012-5350Oct 9, 2012
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in a paywithtweet shortcode.

  • CVE-2012-5348Oct 9, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php.

  • CVE-2012-5342Oct 9, 2012
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php.

  • CVE-2012-5334Oct 8, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter.

  • CVE-2012-5333Oct 8, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2012-5313Oct 8, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter.

  • CVE-2012-5312Oct 8, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2010-5063Oct 8, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter.

  • CVE-2012-5294Oct 4, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2011-5203Oct 4, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2012-5292Oct 4, 2012
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Atar2b CMS 4.0.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) gallery_e.php, (2) pageE.php, or (3) pageH.php.

  • CVE-2012-5291Oct 4, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in team.php in Posse Softball Director CMS allows remote attackers to execute arbitrary SQL commands via the idteam parameter.

  • CVE-2012-5288Oct 4, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2012-1603Oct 1, 2012
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in ajaxserver.php in NextBBS 0.6 allow remote attackers to execute arbitrary SQL commands via the (1) curstr parameter in the findUsers function, (2) id parameter in the isIdAvailable function, or (3) username parameter in the getGreetings…

  • CVE-2012-5227Oct 1, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2012-2998Sep 28, 2012
    risk 0.03cvss epss 0.06

    SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2012-1116Sep 26, 2012
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2012-5098Sep 23, 2012
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php.

  • CVE-2011-5200Sep 23, 2012
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in DeDeCMS, possibly 5.6, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) list.php, (2) members.php, or (3) book.php.