VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,295)

page 809 of 1,015
  • CVE-2010-2142Jun 2, 2010
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-2141Jun 2, 2010
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action.

  • CVE-2010-2135Jun 2, 2010
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.

  • CVE-2010-2134Jun 2, 2010
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

  • CVE-2010-2133Jun 2, 2010
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.

  • CVE-2010-2124Jun 1, 2010
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-2051May 25, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in article.php in Debliteck DBCart allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2010-2047May 25, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action. NOTE: some of these details are obtained from third party information.

  • CVE-2010-2044May 25, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php.

  • CVE-2010-2042May 25, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2010-2016May 24, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter.

  • CVE-2010-2015May 24, 2010
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php.

  • CVE-2010-1994May 20, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO.

  • CVE-2010-1950May 19, 2010
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this…

  • CVE-2010-1949May 19, 2010
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2010-1925May 12, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-2817.

  • CVE-2010-1924May 12, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter.

  • CVE-2010-1923May 12, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.

  • CVE-2010-1918May 12, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter.

  • CVE-2010-1877May 12, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php.