VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 98 of 1,043
  • CVE-2023-27844CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component.

  • CVE-2023-1723CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection. This issue affects Mobile Assistant: before 21.S.2343.

  • CVE-2023-1863CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06.

  • CVE-2023-29622CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.

  • CVE-2023-27667CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.

  • CVE-2023-27779CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.01

    AM Presencia v3.7.3 was discovered to contain a SQL injection vulnerability via the user parameter in the login form.

  • CVE-2023-29598CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.01

    lmxcms v1.4.1 was discovered to contain a SQL injection vulnerability via the setbook parameter at index.php.

  • CVE-2023-27032CriApr 12, 2023
    risk 0.64cvss 9.8epss 0.03

    Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().

  • CVE-2023-25330CriApr 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop…

  • CVE-2023-26750CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.

  • CVE-2020-20915CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.

  • CVE-2020-20914CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.

  • CVE-2020-20913CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.

  • CVE-2022-38923CriApr 3, 2023
    risk 0.64cvss 9.8epss 0.01

    BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.

  • CVE-2022-38922CriApr 3, 2023
    risk 0.64cvss 9.8epss 0.01

    BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.

  • CVE-2023-1765CriApr 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection. This issue affects Panon: before 1.0.2.

  • CVE-2023-26858CriMar 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.

  • CVE-2022-36979CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within…

  • CVE-2022-36976CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the GroupDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An…

  • CVE-2022-36975CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An…