CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 134 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22880 | Cri | 0.64 | 9.8 | 0.01 | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId. | ||
| CVE-2021-3242 | Cri | 0.64 | 9.8 | 0.01 | Feb 16, 2022 | DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=. | ||
| CVE-2022-23358 | Cri | 0.64 | 9.8 | 0.01 | Feb 16, 2022 | EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement. | ||
| CVE-2022-24206 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter. | ||
| CVE-2022-23902 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter. | ||
| CVE-2022-23337 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2022 | DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter. | ||
| CVE-2022-23336 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2022 | S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter. | ||
| CVE-2022-23335 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2022 | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter. | ||
| CVE-2022-22295 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2022 | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter. | ||
| CVE-2021-34235 | Cri | 0.64 | 9.8 | 0.02 | Feb 11, 2022 | Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page. | ||
| CVE-2022-23379 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2022 | Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid(). | ||
| CVE-2022-24222 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | ||
| CVE-2022-24221 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. | ||
| CVE-2022-24220 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | ||
| CVE-2022-24219 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | ||
| CVE-2021-43510 | Cri | 0.64 | 9.8 | 0.08 | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. | ||
| CVE-2021-43509 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php. | ||
| CVE-2021-46448 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID. | ||
| CVE-2021-46446 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID. | ||
| CVE-2021-46445 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id. |
- risk 0.64cvss 9.8epss 0.01
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
- risk 0.64cvss 9.8epss 0.01
DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.
- risk 0.64cvss 9.8epss 0.01
EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.
- risk 0.64cvss 9.8epss 0.01
Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter.
- risk 0.64cvss 9.8epss 0.02
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
- risk 0.64cvss 9.8epss 0.01
S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
- risk 0.64cvss 9.8epss 0.02
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.
- risk 0.64cvss 9.8epss 0.02
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.
- risk 0.64cvss 9.8epss 0.02
Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.
- risk 0.64cvss 9.8epss 0.01
Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
- risk 0.64cvss 9.8epss 0.01
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.
- risk 0.64cvss 9.8epss 0.08
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.
- risk 0.64cvss 9.8epss 0.01
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=1&cID.
- risk 0.64cvss 9.8epss 0.01
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=admin_access_group_edit&aagID.
- risk 0.64cvss 9.8epss 0.01
H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_group_id.