CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 136 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23365 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php. | ||
| CVE-2022-23364 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php. | ||
| CVE-2022-23363 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php. | ||
| CVE-2021-40595 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2022 | SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php. | ||
| CVE-2021-40247 | Cri | 0.64 | 9.8 | 0.03 | Jan 21, 2022 | SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field. | ||
| CVE-2021-46309 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter. | ||
| CVE-2021-46308 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter. | ||
| CVE-2021-46307 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php. | ||
| CVE-2021-46201 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node. | ||
| CVE-2021-46200 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php. | ||
| CVE-2021-46198 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app. | ||
| CVE-2022-23314 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do. | ||
| CVE-2021-46061 | Cri | 0.64 | 9.8 | 0.02 | Jan 20, 2022 | An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app. | ||
| CVE-2021-44245 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters. | ||
| CVE-2021-44244 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php. | ||
| CVE-2021-44092 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form. | ||
| CVE-2021-44090 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter. | ||
| CVE-2021-46204 | Cri | 0.64 | 9.8 | 0.01 | Jan 19, 2022 | Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php. | ||
| CVE-2022-22055 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2022 | The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’s privilege and perform arbitrary operations on the system or disrupt service. | ||
| CVE-2020-28103 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2022 | cscms v4.1 allows for SQL injection via the "page_del" function. |
- risk 0.64cvss 9.8epss 0.01
HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.
- risk 0.64cvss 9.8epss 0.01
HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.
- risk 0.64cvss 9.8epss 0.01
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.
- risk 0.64cvss 9.8epss 0.02
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
- risk 0.64cvss 9.8epss 0.01
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php.
- risk 0.64cvss 9.8epss 0.02
The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’s privilege and perform arbitrary operations on the system or disrupt service.
- risk 0.64cvss 9.8epss 0.01
cscms v4.1 allows for SQL injection via the "page_del" function.