CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 120 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30512 | Cri | 0.64 | 9.8 | 0.10 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31. | ||
| CVE-2022-30511 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4. | ||
| CVE-2022-30510 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59. | ||
| CVE-2022-30490 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php. | ||
| CVE-2022-30481 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters. | ||
| CVE-2022-30478 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters. | ||
| CVE-2022-30352 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script. | ||
| CVE-2022-29659 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php. | ||
| CVE-2022-24240 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp. | ||
| CVE-2021-44098 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database. | ||
| CVE-2021-44097 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database. | ||
| CVE-2021-44096 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database. | ||
| CVE-2021-44095 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database. | ||
| CVE-2021-26634 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to… | ||
| CVE-2019-12351 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma. | ||
| CVE-2019-12350 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma. | ||
| CVE-2019-12349 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter. | ||
| CVE-2022-30516 | Cri | 0.64 | 9.8 | 0.02 | May 26, 2022 | In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks. | ||
| CVE-2022-30493 | Cri | 0.64 | 9.8 | 0.02 | May 26, 2022 | In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation). | ||
| CVE-2022-30500 | Cri | 0.64 | 9.8 | 0.01 | May 26, 2022 | Jfinal cms 5.1.0 is vulnerable to SQL Injection. |
- risk 0.64cvss 9.8epss 0.10
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
- risk 0.64cvss 9.8epss 0.04
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
- risk 0.64cvss 9.8epss 0.04
School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
- risk 0.64cvss 9.8epss 0.01
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.
- risk 0.64cvss 9.8epss 0.02
Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid parameters.
- risk 0.64cvss 9.8epss 0.02
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters.
- risk 0.64cvss 9.8epss 0.02
phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" parameter in index.php script.
- risk 0.64cvss 9.8epss 0.02
Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.
- risk 0.64cvss 9.8epss 0.01
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
- risk 0.64cvss 9.8epss 0.01
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.
- risk 0.64cvss 9.8epss 0.01
EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.
- risk 0.64cvss 9.8epss 0.01
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
- risk 0.64cvss 9.8epss 0.02
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.
- risk 0.64cvss 9.8epss 0.01
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
- risk 0.64cvss 9.8epss 0.02
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
- risk 0.64cvss 9.8epss 0.02
In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).
- risk 0.64cvss 9.8epss 0.01
Jfinal cms 5.1.0 is vulnerable to SQL Injection.