What MITRE CAPEC-108: Command Line Execution through SQL Injection (Detailed Attack Pattern - Very High Severity) requires
MITRE CAPEC-108 (Command Line Execution through SQL Injection) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Likelihood of attack: Low. Typical severity: Very High. Maps to weaknesses CWE-89, CWE-74, CWE-20, CWE-78, and others.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/108.html
SHA-256 integrity: e6505bc45d6afff15469698328fedb0f5f4c6b6bc87f494c2c16bd2e298ceb20
Primary Citations — 10 traced to source
- MITRE CAPEC-108: Command Line Execution through SQL Injection (https://capec.mitre.org/data/definitions/108.html)
- CWE-89: underlying weakness (http://cwe.mitre.org/data/definitions/89.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.