CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 116 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32094 | Cri | 0.64 | 9.8 | 0.08 | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php. | ||
| CVE-2022-32093 | Cri | 0.64 | 9.8 | 0.02 | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php. | ||
| CVE-2021-32428 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2022 | SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books) 10 via the author_id parameter to api.php. | ||
| CVE-2022-31787 | Cri | 0.64 | 9.8 | 0.01 | Jun 23, 2022 | IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO | ||
| CVE-2022-31361 | Cri | 0.64 | 9.8 | 0.01 | Jun 23, 2022 | Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | ||
| CVE-2022-31941 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=. | ||
| CVE-2022-31357 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=. | ||
| CVE-2022-31356 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=. | ||
| CVE-2022-31355 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=. | ||
| CVE-2022-31296 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2022 | Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php. | ||
| CVE-2021-41408 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. | ||
| CVE-2021-41487 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'. | ||
| CVE-2022-31384 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php. | ||
| CVE-2022-31383 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php. | ||
| CVE-2022-31382 | Cri | 0.64 | 9.8 | 0.02 | Jun 16, 2022 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php. | ||
| CVE-2021-41654 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2022 | SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php | ||
| CVE-2022-32301 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php. | ||
| CVE-2022-32101 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php. | ||
| CVE-2019-4575 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2022 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end… | ||
| CVE-2022-32337 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=. |
- risk 0.64cvss 9.8epss 0.08
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books) 10 via the author_id parameter to api.php.
- risk 0.64cvss 9.8epss 0.01
IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO
- risk 0.64cvss 9.8epss 0.01
Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
- risk 0.64cvss 9.8epss 0.02
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
- risk 0.64cvss 9.8epss 0.01
VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.
- risk 0.64cvss 9.8epss 0.02
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
- risk 0.64cvss 9.8epss 0.02
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php
- risk 0.64cvss 9.8epss 0.01
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php.
- risk 0.64cvss 9.8epss 0.01
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.
- risk 0.64cvss 9.8epss 0.01
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end…
- risk 0.64cvss 9.8epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=.