VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 96 of 1,043
  • CVE-2023-33509CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.

  • CVE-2023-33734CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.

  • CVE-2023-33280CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

  • CVE-2023-33279CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

  • CVE-2023-33278CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

  • CVE-2023-2851CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware also EOS when CVE-ID assigned.

  • CVE-2023-2064CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20.

  • CVE-2023-2045CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4.

  • CVE-2023-2750CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05.

  • CVE-2023-1508CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3.

  • CVE-2023-31752CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.

  • CVE-2023-33361CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.

  • CVE-2023-33338CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.04

    Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.

  • CVE-2023-31707CriMay 19, 2023
    risk 0.64cvss 9.8epss 0.01

    SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.

  • CVE-2023-29985CriMay 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.

  • CVE-2023-30191CriMay 17, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().

  • CVE-2023-30189CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().

  • CVE-2023-27742CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.

  • CVE-2023-31519CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php.

  • CVE-2023-30245CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file.