VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 93 of 1,043
  • CVE-2023-34477CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-34476CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-23758CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-23757CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-33367CriAug 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.

  • CVE-2023-39551CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.

  • CVE-2023-33665CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

  • CVE-2023-33666CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.01

    ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.

  • CVE-2023-36213CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.

  • CVE-2023-38954CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.01

    ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.

  • CVE-2023-39122CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).

  • CVE-2023-37771CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.

  • CVE-2020-21662CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.

  • CVE-2023-37647CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.

  • CVE-2023-26859CriJul 26, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.

  • CVE-2023-35066CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701.

  • CVE-2023-3046CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection. This issue affects Scienta: before 20230630.1953.

  • CVE-2023-31753CriJul 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.

  • CVE-2023-37165CriJul 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.

  • CVE-2023-30153CriJul 18, 2023
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller.