CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 112 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36683 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment. | ||
| CVE-2022-36682 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student. | ||
| CVE-2022-36681 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account. | ||
| CVE-2022-36680 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. | ||
| CVE-2022-36679 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user. | ||
| CVE-2022-36678 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category. | ||
| CVE-2022-36719 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php. | ||
| CVE-2022-36716 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php. | ||
| CVE-2022-36715 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php. | ||
| CVE-2022-36697 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste. | ||
| CVE-2022-36696 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout. | ||
| CVE-2022-36695 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin. | ||
| CVE-2022-36693 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item. | ||
| CVE-2022-36692 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category. | ||
| CVE-2021-43329 | Cri | 0.64 | 9.8 | 0.03 | Aug 25, 2022 | A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter. | ||
| CVE-2022-35115 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2022 | IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php. | ||
| CVE-2022-37112 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2022 | BlueCMS 1.6 has SQL injection in line 55 of admin/model.php | ||
| CVE-2022-37111 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2022 | BlueCMS 1.6 has SQL injection in line 132 of admin/article.php | ||
| CVE-2022-37223 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. | ||
| CVE-2022-37199 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. |
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/changestock.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/search.php.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.03
A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute arbitrary SQL commands via the license parameter.
- risk 0.64cvss 9.8epss 0.01
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
- risk 0.64cvss 9.8epss 0.01
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
- risk 0.64cvss 9.8epss 0.01
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
- risk 0.64cvss 9.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
- risk 0.64cvss 9.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.