CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 119 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31346 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_service. | ||
| CVE-2022-31345 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=. | ||
| CVE-2022-31344 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_booking. | ||
| CVE-2022-31343 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=. | ||
| CVE-2022-31340 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php. | ||
| CVE-2022-31338 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=. | ||
| CVE-2022-31337 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=. | ||
| CVE-2022-31336 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php. | ||
| CVE-2022-31335 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=. | ||
| CVE-2022-31329 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php. | ||
| CVE-2022-31328 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=. | ||
| CVE-2022-31327 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=. | ||
| CVE-2022-30817 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php. | ||
| CVE-2022-30816 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php. | ||
| CVE-2022-30815 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar= | ||
| CVE-2022-30814 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php. | ||
| CVE-2022-30813 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php. | ||
| CVE-2022-30810 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php. | ||
| CVE-2022-30809 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=. | ||
| CVE-2022-30797 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. |
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_service.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_booking.
- risk 0.64cvss 9.8epss 0.01
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=.
- risk 0.64cvss 9.8epss 0.01
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.
- risk 0.64cvss 9.8epss 0.01
Simple Bus Ticket Booking System 1.0 is vulnerable to SQL Injection via /SimpleBusTicket/index.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar=
- risk 0.64cvss 9.8epss 0.01
elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php.
- risk 0.64cvss 9.8epss 0.01
elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.
- risk 0.64cvss 9.8epss 0.01
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.