VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 8 of 1,041
  • CVE-2018-6228CriMar 15, 2018
    risk 0.68cvss 9.8epss 0.10

    A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

  • CVE-2018-7313CriFeb 22, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.

  • CVE-2018-6583CriFeb 17, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.

  • CVE-2018-6006CriFeb 17, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.

  • CVE-2017-17420CriFeb 8, 2018
    risk 0.68cvss 9.8epss 0.48

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUJobCountHistory Get method…

  • CVE-2017-17417CriFeb 8, 2018
    risk 0.68cvss 9.8epss 0.10

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUPhaseStatus Acknowledge method…

  • CVE-2018-5973CriJan 25, 2018
    risk 0.68cvss 9.8epss 0.20

    SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.

  • CVE-2018-5988CriJan 24, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.

  • CVE-2018-5985CriJan 24, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.

  • CVE-2018-5979CriJan 24, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.

  • CVE-2018-5972CriJan 24, 2018
    risk 0.68cvss 9.8epss 0.19

    SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.

  • CVE-2017-7997CriJan 8, 2018
    risk 0.68cvss 9.8epss 0.19

    Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users/blhistory.jsp or (3) webapp/users/prhistory.jsp.

  • CVE-2017-14078CriSep 22, 2017
    risk 0.68cvss 9.8epss 0.50

    SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

  • CVE-2015-9098CriJun 22, 2017
    risk 0.68cvss 9.8epss 0.14

    In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability to execute arbitrary SQL commands on any monitored Microsoft SQL Server machines. If the Base Monitor is connecting to these…

  • CVE-2017-2641CriMar 26, 2017
    risk 0.68cvss 9.8epss 0.15

    In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

  • CVE-2025-32429CriJul 24, 2025
    risk 0.67cvss 9.8epss 0.85

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's…

  • CVE-2025-32814CriMay 22, 2025
    risk 0.67cvss 9.8epss 0.36

    An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.

  • CVE-2025-22954CriMar 12, 2025
    risk 0.67cvss 10.0epss 0.26

    GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.

  • CVE-2024-42327CriNov 27, 2024
    risk 0.67cvss 9.9epss 0.79

    A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function…

  • CVE-2024-50672CriNov 25, 2024
    risk 0.67cvss 9.8epss 0.02

    A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature. The vulnerability occurs due to insufficient validation of user input, which is…