CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 123 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22413 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022. | ||
| CVE-2022-29995 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=clients/manage_client&id=. | ||
| CVE-2022-29994 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=. | ||
| CVE-2022-29993 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/bookings/view_booking.php?id=. | ||
| CVE-2022-29992 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=. | ||
| CVE-2022-29990 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/view_category.php?id=. | ||
| CVE-2022-29989 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking. | ||
| CVE-2022-29988 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete. | ||
| CVE-2022-29987 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=. | ||
| CVE-2022-29986 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility. | ||
| CVE-2022-29985 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category. | ||
| CVE-2022-29984 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=. | ||
| CVE-2022-29983 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=. | ||
| CVE-2022-29982 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=. | ||
| CVE-2022-29981 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete. | ||
| CVE-2022-29980 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-29979 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation. | ||
| CVE-2022-29751 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client. | ||
| CVE-2022-29750 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service. | ||
| CVE-2022-29749 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice. |
- risk 0.64cvss 9.8epss 0.01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=clients/manage_client&id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/bookings/view_booking.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/manage_category.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/categories/view_category.php?id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=client/view_client&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.