CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 110 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37204 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2022 | Final CMS 5.1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-38509 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php. | ||
| CVE-2022-37203 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-40766 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2022 | Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring. | ||
| CVE-2022-37138 | Cri | 0.64 | 9.8 | 0.01 | Sep 14, 2022 | Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form. | ||
| CVE-2022-36669 | Cri | 0.64 | 9.8 | 0.03 | Sep 14, 2022 | Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. | ||
| CVE-2022-38771 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request. | ||
| CVE-2022-38637 | Cri | 0.64 | 9.8 | 0.06 | Sep 13, 2022 | Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page. | ||
| CVE-2022-38542 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above. | ||
| CVE-2022-38541 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface. | ||
| CVE-2022-38540 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface. | ||
| CVE-2022-38539 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply. | ||
| CVE-2022-38538 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module. | ||
| CVE-2022-38537 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2022 | Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface. | ||
| CVE-2022-37794 | Cri | 0.64 | 9.8 | 0.01 | Sep 12, 2022 | In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection. | ||
| CVE-2021-44835 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2022 | An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection. | ||
| CVE-2022-38250 | Cri | 0.64 | 9.8 | 0.03 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page. | ||
| CVE-2020-22669 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2022 | Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web… | ||
| CVE-2022-36609 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2022 | Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php. | ||
| CVE-2022-36594 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2022 | Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function. |
- risk 0.64cvss 9.8epss 0.01
Final CMS 5.1.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.
- risk 0.64cvss 9.8epss 0.02
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.64cvss 9.8epss 0.01
Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring.
- risk 0.64cvss 9.8epss 0.01
Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.
- risk 0.64cvss 9.8epss 0.03
Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
- risk 0.64cvss 9.8epss 0.01
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.
- risk 0.64cvss 9.8epss 0.06
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.
- risk 0.64cvss 9.8epss 0.01
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above.
- risk 0.64cvss 9.8epss 0.01
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.
- risk 0.64cvss 9.8epss 0.01
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.
- risk 0.64cvss 9.8epss 0.01
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.
- risk 0.64cvss 9.8epss 0.01
Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module.
- risk 0.64cvss 9.8epss 0.01
Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface.
- risk 0.64cvss 9.8epss 0.01
In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection.
- risk 0.64cvss 9.8epss 0.03
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.
- risk 0.64cvss 9.8epss 0.01
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web…
- risk 0.64cvss 9.8epss 0.01
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
- risk 0.64cvss 9.8epss 0.01
Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.