VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,295)

page 855 of 1,015
  • CVE-2009-0426Feb 5, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2009-0425Feb 5, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the clanek parameter.

  • CVE-2009-0421Feb 5, 2009
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

  • CVE-2009-0420Feb 5, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2008-6050Feb 4, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php.

  • CVE-2009-0409Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2009-0407Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2009-0406Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2009-0405Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter.

  • CVE-2009-0403Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

  • CVE-2009-0400Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

  • CVE-2008-6043Feb 3, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL commands via the (1) order_field and (2) order_type parameters to categories.php and unspecified other components. NOTE: some of these details are obtained from…

  • CVE-2008-6042Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php.

  • CVE-2008-6038Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php.

  • CVE-2008-6037Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the v parameter.

  • CVE-2008-6033Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-6032Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-6031Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported that 2.34 is also vulnerable.

  • CVE-2008-6030Feb 3, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL commands via (1) the job parameter to index.php in the search module or (2) the news_id parameter to index.php.

  • CVE-2008-6029Feb 3, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search.php in BuzzyWall 1.3.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.