CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 121 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29650 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2022 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php. | ||
| CVE-2022-28862 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2022 | In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized (and unexpected)… | ||
| CVE-2022-30838 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status | ||
| CVE-2022-30461 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2022 | Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id | ||
| CVE-2022-30455 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2022 | Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id. | ||
| CVE-2022-30454 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2022 | Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product. | ||
| CVE-2022-1014 | Cri | 0.64 | 9.8 | 0.02 | May 23, 2022 | The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability. | ||
| CVE-2022-30886 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php. | ||
| CVE-2022-30518 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php. | ||
| CVE-2022-28105 | Cri | 0.64 | 9.8 | 0.01 | May 20, 2022 | Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /scbs/view_facility.php. | ||
| CVE-2022-26633 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php. | ||
| CVE-2022-26632 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php. | ||
| CVE-2022-28962 | Cri | 0.64 | 9.8 | 0.02 | May 19, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client. | ||
| CVE-2021-37413 | Cri | 0.64 | 9.8 | 0.02 | May 19, 2022 | GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files.… | ||
| CVE-2022-30054 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2022 | In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks. | ||
| CVE-2022-30053 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2022 | In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks. | ||
| CVE-2022-30052 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2022 | In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks. | ||
| CVE-2022-1731 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2022 | Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist. | ||
| CVE-2022-28930 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2022 | ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml.. | ||
| CVE-2022-28929 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php. |
- risk 0.64cvss 9.8epss 0.01
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.
- risk 0.64cvss 9.8epss 0.01
In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized (and unexpected)…
- risk 0.64cvss 9.8epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status
- risk 0.64cvss 9.8epss 0.01
Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id
- risk 0.64cvss 9.8epss 0.01
Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.
- risk 0.64cvss 9.8epss 0.02
The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.02
School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.
- risk 0.64cvss 9.8epss 0.02
ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /scbs/view_facility.php.
- risk 0.64cvss 9.8epss 0.02
Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php.
- risk 0.64cvss 9.8epss 0.02
Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /products/view_product.php.
- risk 0.64cvss 9.8epss 0.02
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.
- risk 0.64cvss 9.8epss 0.02
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files.…
- risk 0.64cvss 9.8epss 0.01
In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.
- risk 0.64cvss 9.8epss 0.01
In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks.
- risk 0.64cvss 9.8epss 0.01
In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.
- risk 0.64cvss 9.8epss 0.01
Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.
- risk 0.64cvss 9.8epss 0.01
ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..
- risk 0.64cvss 9.8epss 0.02
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php.