VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,295)

page 843 of 1,015
  • CVE-2008-6606Apr 6, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-6596Apr 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL commands via the hash parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2008-6593Apr 3, 2009
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code into comments.dat via the dlid parameter to index.php.

  • CVE-2009-1229Apr 2, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter.

  • CVE-2009-1224Apr 2, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter.

  • CVE-2008-6582Apr 2, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

  • CVE-2008-6572Mar 31, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

  • CVE-2009-1066Mar 26, 2009
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request.

  • CVE-2008-6527Mar 25, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.

  • CVE-2008-6526Mar 25, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838.

  • CVE-2008-6525Mar 25, 2009
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL commands via the Password parameter (aka the pass field).

  • CVE-2008-6517Mar 25, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in NewsHOWLER 1.03 Beta allows remote attackers to execute arbitrary SQL commands via the news_user cookie parameter.

  • CVE-2009-1049Mar 24, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-6509Mar 23, 2009
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.

  • CVE-2009-1038Mar 20, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif…

  • CVE-2009-1033Mar 20, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.

  • CVE-2009-1032Mar 20, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter.

  • CVE-2009-1026Mar 20, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

  • CVE-2009-1024Mar 20, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL commands via the linkid parameter to edlink.php, and unspecified other vectors.

  • CVE-2009-1023Mar 20, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in phpComasy 0.9.1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.