CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 105 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44015 | Cri | 0.64 | 9.8 | 0.01 | Dec 25, 2022 | An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure. | ||
| CVE-2022-1887 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2022 | The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101. | ||
| CVE-2021-31650 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter. | ||
| CVE-2022-46072 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2022 | Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection. | ||
| CVE-2022-46071 | Cri | 0.64 | 9.8 | 0.04 | Dec 14, 2022 | There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access. | ||
| CVE-2022-41272 | Cri | 0.64 | 9.9 | 0.01 | Dec 13, 2022 | An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to… | ||
| CVE-2022-45010 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2022 | Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php. | ||
| CVE-2022-44945 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter. | ||
| CVE-2022-44291 | Cri | 0.64 | 9.8 | 0.04 | Dec 2, 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. | ||
| CVE-2022-44290 | Cri | 0.64 | 9.8 | 0.04 | Dec 2, 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. | ||
| CVE-2022-2807 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11. | ||
| CVE-2022-30528 | Cri | 0.64 | 9.8 | 0.01 | Dec 1, 2022 | SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php. | ||
| CVE-2022-44151 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2022 | Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php. | ||
| CVE-2022-42109 | Cri | 0.64 | 9.8 | 0.01 | Nov 29, 2022 | Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php. | ||
| CVE-2022-44399 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php. | ||
| CVE-2022-36193 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries. | ||
| CVE-2022-44120 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php. | ||
| CVE-2022-44117 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL. | ||
| CVE-2021-35284 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1. | ||
| CVE-2022-44139 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php. |
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.
- risk 0.64cvss 9.8epss 0.01
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.
- risk 0.64cvss 9.8epss 0.01
Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.
- risk 0.64cvss 9.8epss 0.04
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
- risk 0.64cvss 9.9epss 0.01
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to…
- risk 0.64cvss 9.8epss 0.01
Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.
- risk 0.64cvss 9.8epss 0.01
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
- risk 0.64cvss 9.8epss 0.04
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
- risk 0.64cvss 9.8epss 0.04
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.
- risk 0.64cvss 9.8epss 0.01
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
- risk 0.64cvss 9.8epss 0.01
Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.
- risk 0.64cvss 9.8epss 0.01
Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
- risk 0.64cvss 9.8epss 0.01
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
- risk 0.64cvss 9.8epss 0.01
Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.
- risk 0.64cvss 9.8epss 0.01
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.