CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 106 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43213 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. | ||
| CVE-2022-43212 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php. | ||
| CVE-2022-43215 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php. | ||
| CVE-2022-43214 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. | ||
| CVE-2022-44785 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2022 | An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter. | ||
| CVE-2022-39180 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page | ||
| CVE-2022-36787 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE. | ||
| CVE-2022-42245 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2022 | Dreamer CMS 4.0.01 is vulnerable to SQL Injection. | ||
| CVE-2022-44003 | Cri | 0.64 | 9.8 | 0.02 | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations. | ||
| CVE-2022-43135 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php. | ||
| CVE-2022-43262 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php. | ||
| CVE-2022-43256 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php. | ||
| CVE-2022-42122 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. | ||
| CVE-2022-42984 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients. | ||
| CVE-2022-43058 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity. | ||
| CVE-2022-3481 | Cri | 0.64 | 9.8 | 0.04 | Nov 7, 2022 | The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection | ||
| CVE-2022-42744 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2022 | CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks. | ||
| CVE-2020-22820 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2022 | MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter. | ||
| CVE-2020-22819 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2022 | MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter. | ||
| CVE-2020-22818 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2022 | MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter. |
- risk 0.64cvss 9.8epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.
- risk 0.64cvss 9.8epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.
- risk 0.64cvss 9.8epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.
- risk 0.64cvss 9.8epss 0.01
College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page
- risk 0.64cvss 9.8epss 0.01
webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.
- risk 0.64cvss 9.8epss 0.01
Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.
- risk 0.64cvss 9.8epss 0.01
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.
- risk 0.64cvss 9.8epss 0.01
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
- risk 0.64cvss 9.8epss 0.01
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.
- risk 0.64cvss 9.8epss 0.04
The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection
- risk 0.64cvss 9.8epss 0.01
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.
- risk 0.64cvss 9.8epss 0.01
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
- risk 0.64cvss 9.8epss 0.01
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
- risk 0.64cvss 9.8epss 0.01
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.