CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 12 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16894 | Cri | 0.67 | 9.8 | 0.03 | Sep 26, 2019 | download.php in inoERP 4.15 allows SQL injection through insecure deserialization. | ||
| CVE-2019-16693 | Cri | 0.67 | 9.8 | 0.04 | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. | ||
| CVE-2019-14314 | Cri | 0.67 | 9.8 | 0.43 | Aug 27, 2019 | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package… | ||
| CVE-2019-13292 | Cri | 0.67 | 9.8 | 0.09 | Jul 4, 2019 | A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks. | ||
| CVE-2019-10866 | Cri | 0.67 | 9.8 | 0.06 | May 23, 2019 | In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter. | ||
| CVE-2019-12279 | Cri | 0.67 | 9.8 | 0.04 | May 22, 2019 | Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any… | ||
| CVE-2019-8923 | Cri | 0.67 | 9.8 | 0.04 | May 14, 2019 | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued. | ||
| CVE-2018-18800 | Cri | 0.67 | 9.8 | 0.03 | May 14, 2019 | The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php. | ||
| CVE-2019-5722 | Cri | 0.67 | 9.8 | 0.04 | Mar 21, 2019 | An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number. | ||
| CVE-2018-18798 | Cri | 0.67 | 9.8 | 0.03 | Mar 21, 2019 | Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view. | ||
| CVE-2019-9184 | Cri | 0.67 | 9.8 | 0.09 | Feb 26, 2019 | SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter. | ||
| CVE-2018-13045 | Cri | 0.67 | 9.8 | 0.03 | Jan 2, 2019 | SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter. | ||
| CVE-2018-18923 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2018 | AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php. | ||
| CVE-2018-18619 | Cri | 0.67 | 9.8 | 0.04 | Nov 29, 2018 | internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in… | ||
| CVE-2018-18805 | Cri | 0.67 | 9.8 | 0.05 | Nov 16, 2018 | Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. | ||
| CVE-2018-18804 | Cri | 0.67 | 9.8 | 0.03 | Nov 16, 2018 | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. | ||
| CVE-2018-18803 | Cri | 0.67 | 9.8 | 0.03 | Nov 16, 2018 | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. | ||
| CVE-2018-18801 | Cri | 0.67 | 9.8 | 0.03 | Nov 16, 2018 | The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL]. | ||
| CVE-2018-18795 | Cri | 0.67 | 9.8 | 0.03 | Nov 16, 2018 | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | ||
| CVE-2018-18763 | Cri | 0.67 | 9.8 | 0.03 | Nov 16, 2018 | SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. |
- risk 0.67cvss 9.8epss 0.03
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
- risk 0.67cvss 9.8epss 0.04
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
- risk 0.67cvss 9.8epss 0.43
A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package…
- risk 0.67cvss 9.8epss 0.09
A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.
- risk 0.67cvss 9.8epss 0.06
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
- risk 0.67cvss 9.8epss 0.04
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any…
- risk 0.67cvss 9.8epss 0.04
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
- risk 0.67cvss 9.8epss 0.03
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php.
- risk 0.67cvss 9.8epss 0.04
An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.
- risk 0.67cvss 9.8epss 0.03
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.
- risk 0.67cvss 9.8epss 0.09
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.
- risk 0.67cvss 9.8epss 0.03
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.
- risk 0.67cvss 9.8epss 0.03
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php.
- risk 0.67cvss 9.8epss 0.04
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in…
- risk 0.67cvss 9.8epss 0.05
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
- risk 0.67cvss 9.8epss 0.03
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
- risk 0.67cvss 9.8epss 0.03
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.
- risk 0.67cvss 9.8epss 0.03
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].
- risk 0.67cvss 9.8epss 0.03
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
- risk 0.67cvss 9.8epss 0.03
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.