CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 113 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36198 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2022 | Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and… | ||
| CVE-2022-36030 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2022 | Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes… | ||
| CVE-2022-36578 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | jizhicms v2.3.1 has SQL injection in the background. | ||
| CVE-2022-36606 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database. | ||
| CVE-2022-36605 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter. | ||
| CVE-2022-36729 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php. | ||
| CVE-2022-36728 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php. | ||
| CVE-2022-36727 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php. | ||
| CVE-2022-36725 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php. | ||
| CVE-2022-36722 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php. | ||
| CVE-2022-35175 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php. | ||
| CVE-2022-35154 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter. | ||
| CVE-2022-35606 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.' | ||
| CVE-2022-35605 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc. | ||
| CVE-2022-35603 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. | ||
| CVE-2022-35602 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user. | ||
| CVE-2022-35601 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt. | ||
| CVE-2022-35599 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode. | ||
| CVE-2022-35598 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2022 | A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username. | ||
| CVE-2022-35121 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2022 | Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. |
- risk 0.64cvss 9.8epss 0.01
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and…
- risk 0.64cvss 9.8epss 0.01
Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes…
- risk 0.64cvss 9.8epss 0.01
jizhicms v2.3.1 has SQL injection in the background.
- risk 0.64cvss 9.8epss 0.01
Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
- risk 0.64cvss 9.8epss 0.01
Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php.
- risk 0.64cvss 9.8epss 0.01
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php.
- risk 0.64cvss 9.8epss 0.01
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php.
- risk 0.64cvss 9.8epss 0.01
Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameter 'customerCode.'
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as 'users', 'pass', etc.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter user.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter productcode.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.
- risk 0.64cvss 9.8epss 0.01
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.