CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 131 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26013 | Cri | 0.64 | 9.8 | 0.09 | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-25980 | Cri | 0.64 | 9.8 | 0.01 | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-25880 | Cri | 0.64 | 9.8 | 0.01 | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-0923 | Cri | 0.64 | 9.8 | 0.01 | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-0846 | Cri | 0.64 | 9.8 | 0.09 | Mar 28, 2022 | The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users | ||
| CVE-2022-0787 | Cri | 0.64 | 9.8 | 0.09 | Mar 28, 2022 | The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections | ||
| CVE-2021-25070 | Cri | 0.64 | 9.8 | 0.02 | Mar 28, 2022 | The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue | ||
| CVE-2022-23882 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2022 | TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php. | ||
| CVE-2021-44617 | Cri | 0.64 | 9.8 | 0.02 | Mar 28, 2022 | A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated. | ||
| CVE-2022-26268 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2022 | Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php. | ||
| CVE-2022-26301 | Cri | 0.64 | 9.8 | 0.01 | Mar 24, 2022 | TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php. | ||
| CVE-2021-43084 | Cri | 0.64 | 9.8 | 0.01 | Mar 24, 2022 | An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter. | ||
| CVE-2021-43700 | Cri | 0.64 | 9.8 | 0.01 | Mar 24, 2022 | An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8. | ||
| CVE-2022-25222 | Cri | 0.64 | 9.8 | 0.02 | Mar 23, 2022 | Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter. | ||
| CVE-2021-43735 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2022 | CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule. | ||
| CVE-2022-25517 | Cri | 0.64 | 9.8 | 0.02 | Mar 22, 2022 | MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior. | ||
| CVE-2022-26285 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | ||
| CVE-2022-26284 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | ||
| CVE-2022-26283 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | ||
| CVE-2022-0694 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an… |
- risk 0.64cvss 9.8epss 0.09
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.01
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.64cvss 9.8epss 0.09
The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users
- risk 0.64cvss 9.8epss 0.09
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
- risk 0.64cvss 9.8epss 0.02
The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue
- risk 0.64cvss 9.8epss 0.01
TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.
- risk 0.64cvss 9.8epss 0.02
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
- risk 0.64cvss 9.8epss 0.01
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.
- risk 0.64cvss 9.8epss 0.01
TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.
- risk 0.64cvss 9.8epss 0.02
Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.
- risk 0.64cvss 9.8epss 0.01
CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.
- risk 0.64cvss 9.8epss 0.02
MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.
- risk 0.64cvss 9.8epss 0.02
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.02
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.02
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an…