CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 118 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31969 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=user/manage_user&id=. | ||
| CVE-2022-31965 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/respondent_types/manage_respondent_type.php?id=. | ||
| CVE-2022-31964 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/respondent_types/view_respondent_type.php?id=. | ||
| CVE-2022-31962 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/view_incident.php?id=. | ||
| CVE-2022-31961 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/manage_incident.php?id=. | ||
| CVE-2022-31959 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/teams/manage_team.php?id=. | ||
| CVE-2022-31957 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/teams/view_team.php?id=. | ||
| CVE-2022-31956 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/manage_report.php?id=. | ||
| CVE-2022-31953 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/view_report.php?id=. | ||
| CVE-2022-31952 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL injection via /rdms/classes/Master.php?f=delete_incident. | ||
| CVE-2022-31951 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_respondent_type. | ||
| CVE-2022-31948 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report. | ||
| CVE-2022-31946 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_team. | ||
| CVE-2022-31354 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service. | ||
| CVE-2022-31353 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/services/view_service.php?id=. | ||
| CVE-2022-31352 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=. | ||
| CVE-2022-31351 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=. | ||
| CVE-2022-31350 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=. | ||
| CVE-2022-31348 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/update_status.php?id=. | ||
| CVE-2022-31347 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle. |
- risk 0.64cvss 9.8epss 0.01
ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/respondent_types/manage_respondent_type.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/respondent_types/view_respondent_type.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/view_incident.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/manage_incident.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/teams/manage_team.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/teams/view_team.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/manage_report.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/view_report.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL injection via /rdms/classes/Master.php?f=delete_incident.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_respondent_type.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_team.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=get_vehicle_service.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/services/view_service.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection in /ocwbs/admin/services/manage_service.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 by oretnom23 has SQL injection via /ocwbs/admin/services/manage_price.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/update_status.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_vehicle.