VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 99 of 1,043
  • CVE-2022-36972CriMar 29, 2023
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An…

  • CVE-2023-27847CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

  • CVE-2023-26959CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.

  • CVE-2023-28437CriMar 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.

  • CVE-2023-26864CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.

  • CVE-2023-1050CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10.

  • CVE-2023-24655CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.

  • CVE-2023-27638CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions…

  • CVE-2023-27637CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could…

  • CVE-2023-27570CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.

  • CVE-2023-27569CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

  • CVE-2023-1153CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22.

  • CVE-2023-26905CriMar 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id.

  • CVE-2023-1152CriMar 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93.

  • CVE-2023-27041CriMar 16, 2023
    risk 0.64cvss 9.8epss 0.01

    School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php.

  • CVE-2023-27250CriMar 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.

  • CVE-2023-26784CriMar 16, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.

  • CVE-2023-24726CriMar 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.

  • CVE-2023-27074CriMar 14, 2023
    risk 0.64cvss 9.8epss 0.01

    BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.

  • CVE-2023-27052CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.01

    E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php.