VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 95 of 1,043
  • CVE-2023-31672CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.

  • CVE-2023-30150CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

  • CVE-2023-31671CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

  • CVE-2023-34756CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

  • CVE-2023-34755CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

  • CVE-2023-34754CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.03

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

  • CVE-2023-34753CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

  • CVE-2023-34752CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

  • CVE-2023-34751CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

  • CVE-2023-34750CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

  • CVE-2023-34249CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is vulnerable to SQL Injection. This vulnerability has been fixed as of commit dcaeccd37198ecd3e41ea766d1099354b60d69c2. As a workaround, a user may be able to…

  • CVE-2023-35064CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering. This issue affects Satos Mobile: before 20230607.

  • CVE-2023-3047CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection. This issue affects Lockcell: before 15.

  • CVE-2021-4340CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2023-29632CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.

  • CVE-2023-29630CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.

  • CVE-2023-29629CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php.

  • CVE-2023-33762CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a SQL injection vulnerability via the Activity parameter.

  • CVE-2023-28701CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service.

  • CVE-2023-3000CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass. This issue affects ErMon: before 230602.