CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 11 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24442 | Cri | 0.67 | 9.8 | 0.46 | Jul 12, 2021 | The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks | ||
| CVE-2020-18662 | Cri | 0.67 | 9.8 | 0.05 | Jun 24, 2021 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | ||
| CVE-2020-24913 | Cri | 0.67 | 9.8 | 0.41 | Mar 4, 2021 | A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request. | ||
| CVE-2020-35846 | Cri | 0.67 | 9.8 | 0.93 | Dec 30, 2020 | Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. | ||
| CVE-2020-15468 | Cri | 0.67 | 9.8 | 0.03 | Jul 1, 2020 | Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter. | ||
| CVE-2020-15363 | Cri | 0.67 | 9.8 | 0.06 | Jun 28, 2020 | The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection. | ||
| CVE-2020-10549 | Cri | 0.67 | 9.8 | 0.32 | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. | ||
| CVE-2020-10548 | Cri | 0.67 | 9.8 | 0.37 | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. | ||
| CVE-2020-10547 | Cri | 0.67 | 9.8 | 0.37 | Jun 4, 2020 | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. | ||
| CVE-2020-13118 | Cri | 0.67 | 9.8 | 0.04 | May 16, 2020 | An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community. | ||
| CVE-2014-9613 | Cri | 0.67 | 9.8 | 0.04 | Feb 19, 2020 | Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php. | ||
| CVE-2014-9612 | Cri | 0.67 | 9.8 | 0.05 | Feb 19, 2020 | SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter. | ||
| CVE-2012-1124 | Cri | 0.67 | 9.8 | 0.04 | Feb 11, 2020 | SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter. | ||
| CVE-2013-5945 | Cri | 0.67 | 9.8 | 0.10 | Feb 11, 2020 | Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to… | ||
| CVE-2011-4094 | Cri | 0.67 | 9.8 | 0.03 | Jan 21, 2020 | Jara 1.6 has a SQL injection vulnerability. | ||
| CVE-2005-4891 | Cri | 0.67 | 9.8 | 0.02 | Jan 15, 2020 | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements. | ||
| CVE-2012-1259 | Cri | 0.67 | 9.8 | 0.04 | Jan 9, 2020 | Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to… | ||
| CVE-2019-19740 | Cri | 0.67 | 9.8 | 0.06 | Dec 12, 2019 | Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable. | ||
| CVE-2019-19245 | Cri | 0.67 | 9.8 | 0.08 | Dec 2, 2019 | NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used. | ||
| CVE-2011-1939 | Cri | 0.67 | 9.8 | 0.04 | Nov 26, 2019 | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6. |
- risk 0.67cvss 9.8epss 0.46
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks
- risk 0.67cvss 9.8epss 0.05
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
- risk 0.67cvss 9.8epss 0.41
A SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an unauthenticated attacker to access the database by injecting SQL code via a crafted POST request.
- risk 0.67cvss 9.8epss 0.93
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
- risk 0.67cvss 9.8epss 0.03
Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
- risk 0.67cvss 9.8epss 0.06
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
- risk 0.67cvss 9.8epss 0.32
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
- risk 0.67cvss 9.8epss 0.37
rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
- risk 0.67cvss 9.8epss 0.37
rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
- risk 0.67cvss 9.8epss 0.04
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
- risk 0.67cvss 9.8epss 0.04
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php.
- risk 0.67cvss 9.8epss 0.05
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.
- risk 0.67cvss 9.8epss 0.04
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
- risk 0.67cvss 9.8epss 0.10
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to…
- risk 0.67cvss 9.8epss 0.03
Jara 1.6 has a SQL injection vulnerability.
- risk 0.67cvss 9.8epss 0.02
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
- risk 0.67cvss 9.8epss 0.04
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to…
- risk 0.67cvss 9.8epss 0.06
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
- risk 0.67cvss 9.8epss 0.08
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
- risk 0.67cvss 9.8epss 0.04
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.