VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,295)

page 857 of 1,015
  • CVE-2009-0329Jan 29, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844.

  • CVE-2009-0327Jan 29, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.

  • CVE-2009-0326Jan 29, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2009-0324Jan 29, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.

  • CVE-2008-6003Jan 28, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter.

  • CVE-2008-5998Jan 28, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to…

  • CVE-2008-5992Jan 28, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL commands via the KayitNo parameter to (1) diger.php and (2) sayfalar.php.

  • CVE-2008-5988Jan 28, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in scripts/recruit_details.php in Jadu CMS for Government allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2009-0302Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.

  • CVE-2009-0299Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

  • CVE-2009-0297Jan 27, 2009
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.

  • CVE-2009-0296Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

  • CVE-2009-0295Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2009-0293Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.

  • CVE-2009-0292Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.

  • CVE-2009-0284Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

  • CVE-2009-0281Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

  • CVE-2009-0279Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-5978Jan 27, 2009
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.

  • CVE-2008-5977Jan 27, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.