CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 133 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-26171 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter. | ||
| CVE-2022-26170 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | ||
| CVE-2022-26169 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter. | ||
| CVE-2022-25399 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | ||
| CVE-2022-25398 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. | ||
| CVE-2022-25396 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | ||
| CVE-2022-25394 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php. | ||
| CVE-2022-24571 | Cri | 0.64 | 9.8 | 0.02 | Feb 28, 2022 | Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. | ||
| CVE-2022-25096 | Cri | 0.64 | 9.8 | 0.02 | Feb 26, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php. | ||
| CVE-2022-25004 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php. | ||
| CVE-2022-25003 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php. | ||
| CVE-2022-25406 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter. | ||
| CVE-2022-25405 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter. | ||
| CVE-2022-25404 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter. | ||
| CVE-2022-25403 | Cri | 0.64 | 9.8 | 0.02 | Feb 24, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php. | ||
| CVE-2021-44610 | Cri | 0.64 | 9.8 | 0.01 | Feb 24, 2022 | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php. | ||
| CVE-2021-46110 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters. | ||
| CVE-2022-25322 | Cri | 0.64 | 9.8 | 0.08 | Feb 18, 2022 | ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. | ||
| CVE-2021-44868 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2022 | A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do | ||
| CVE-2022-22881 | Cri | 0.64 | 9.8 | 0.01 | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData. |
- risk 0.64cvss 9.8epss 0.01
Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.
- risk 0.64cvss 9.8epss 0.01
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- risk 0.64cvss 9.8epss 0.01
Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- risk 0.64cvss 9.8epss 0.01
Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
- risk 0.64cvss 9.8epss 0.01
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- risk 0.64cvss 9.8epss 0.02
Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php.
- risk 0.64cvss 9.8epss 0.02
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.
- risk 0.64cvss 9.8epss 0.02
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.
- risk 0.64cvss 9.8epss 0.02
Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.
- risk 0.64cvss 9.8epss 0.02
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
- risk 0.64cvss 9.8epss 0.01
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.
- risk 0.64cvss 9.8epss 0.01
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
- risk 0.64cvss 9.8epss 0.08
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
- risk 0.64cvss 9.8epss 0.01
A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do
- risk 0.64cvss 9.8epss 0.01
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.