Standardlikelihood: Highseverity: HighDraft
CAPEC-66SQL Injection
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
High
Description
This attack exploits target software that constructs SQL statements based on user input. An attacker crafts input strings so that when the target software constructs SQL statements based on the input, the resulting SQL statement performs actions other than those the application intended. SQL Injection results from failure of the application to appropriately validate input.
Related weaknesses· 2
Related attack patterns· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-89 | 100% | live |
| Weakness | Improper Validation of Syntactic Correctness of Inputcwe-1286 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.