CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 107 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3254 | Cri | 0.64 | 9.8 | 0.05 | Oct 31, 2022 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | ||
| CVE-2022-43168 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter. | ||
| CVE-2021-38733 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. | ||
| CVE-2021-38732 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. | ||
| CVE-2021-38731 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php. | ||
| CVE-2021-38730 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. | ||
| CVE-2021-38729 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. | ||
| CVE-2021-38217 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php. | ||
| CVE-2021-38737 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php. | ||
| CVE-2021-38736 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php. | ||
| CVE-2021-38734 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php. | ||
| CVE-2021-37782 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2022 | Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php. | ||
| CVE-2022-39976 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2022 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=. | ||
| CVE-2022-43774 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2022 | The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system. | ||
| CVE-2022-42021 | Cri | 0.64 | 9.8 | 0.01 | Oct 20, 2022 | Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=. | ||
| CVE-2022-39056 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2022 | RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database. | ||
| CVE-2022-42237 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2022 | A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account. | ||
| CVE-2022-42064 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2022 | Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell. | ||
| CVE-2022-41391 | Cri | 0.64 | 9.8 | 0.01 | Oct 13, 2022 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. | ||
| CVE-2022-41390 | Cri | 0.64 | 9.8 | 0.01 | Oct 13, 2022 | OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php. |
- risk 0.64cvss 9.8epss 0.05
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection
- risk 0.64cvss 9.8epss 0.01
Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
- risk 0.64cvss 9.8epss 0.01
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
- risk 0.64cvss 9.8epss 0.01
Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
- risk 0.64cvss 9.8epss 0.01
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.
- risk 0.64cvss 9.8epss 0.01
Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=.
- risk 0.64cvss 9.8epss 0.01
RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.
- risk 0.64cvss 9.8epss 0.01
A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.
- risk 0.64cvss 9.8epss 0.01
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
- risk 0.64cvss 9.8epss 0.01
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.