VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 81 of 1,043
  • CVE-2023-51048CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.

  • CVE-2023-6145CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection. This issue affects Softomi Advanced C2C Marketplace…

  • CVE-2023-48434CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48433CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-47990CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.

  • CVE-2023-48384CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

  • CVE-2023-48372CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

  • CVE-2023-48050CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the…

  • CVE-2023-48049CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.

  • CVE-2023-50563CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.

  • CVE-2023-50073CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.

  • CVE-2023-49708CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in Starshop component for Joomla.

  • CVE-2023-49707CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in S5 Register module for Joomla.

  • CVE-2023-48925CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().

  • CVE-2023-46348CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.

  • CVE-2023-40629CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in LMS Lite component for Joomla.

  • CVE-2023-49934CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.

  • CVE-2023-40921CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.

  • CVE-2023-49363CriDec 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.

  • CVE-2023-5008CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.