VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 97 of 1,043
  • CVE-2023-0600CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.04

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

  • CVE-2023-30246CriMay 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the contestant_id parameter.

  • CVE-2023-30192CriMay 12, 2023
    risk 0.64cvss 9.8epss 0.03

    Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

  • CVE-2023-29863CriMay 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

  • CVE-2023-30092CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.

  • CVE-2022-4118CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.01

    The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users

  • CVE-2020-23966CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.

  • CVE-2023-30018CriMay 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.

  • CVE-2023-30242CriMay 5, 2023
    risk 0.64cvss 9.8epss 0.01

    NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.

  • CVE-2023-30203CriMay 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php.

  • CVE-2023-30077CriMay 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.

  • CVE-2023-30204CriMay 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php.

  • CVE-2023-26813CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do.

  • CVE-2023-26781CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

  • CVE-2023-30211CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.01

    OURPHP <= 7.2.0 is vulnerable to SQL Injection.

  • CVE-2023-27843CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.

  • CVE-2023-26865CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.

  • CVE-2023-23753CriApr 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.

  • CVE-2023-30076CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=.

  • CVE-2023-1873CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection. This issue affects Bircard: before 23.04.05.