CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 139 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24731 | Cri | 0.64 | 9.8 | 0.06 | Nov 8, 2021 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an… | ||
| CVE-2021-42077 | Cri | 0.64 | 9.8 | 0.03 | Nov 8, 2021 | PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database… | ||
| CVE-2021-34684 | Cri | 0.64 | 9.8 | 0.06 | Nov 8, 2021 | Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI. | ||
| CVE-2020-22226 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2021 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function. | ||
| CVE-2020-22225 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2021 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. | ||
| CVE-2020-22223 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2021 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function. | ||
| CVE-2021-42670 | Cri | 0.64 | 9.8 | 0.08 | Nov 5, 2021 | A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to… | ||
| CVE-2021-42668 | Cri | 0.64 | 9.8 | 0.05 | Nov 5, 2021 | A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a… | ||
| CVE-2021-42665 | Cri | 0.64 | 9.8 | 0.05 | Nov 5, 2021 | An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication. | ||
| CVE-2021-41492 | Cri | 0.64 | 9.8 | 0.02 | Nov 3, 2021 | Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php. | ||
| CVE-2020-18262 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2021 | ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter. | ||
| CVE-2020-24000 | Cri | 0.64 | 9.8 | 0.02 | Nov 3, 2021 | SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php. | ||
| CVE-2021-43130 | Cri | 0.64 | 9.8 | 0.02 | Nov 3, 2021 | An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php. | ||
| CVE-2020-23685 | Cri | 0.64 | 9.8 | 0.02 | Nov 2, 2021 | SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php. | ||
| CVE-2021-26739 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2021 | SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter. | ||
| CVE-2021-41676 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2021 | An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php. | ||
| CVE-2021-41674 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2021 | An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php. | ||
| CVE-2020-21250 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2021 | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. | ||
| CVE-2020-24932 | Cri | 0.64 | 9.8 | 0.02 | Oct 27, 2021 | An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php. | ||
| CVE-2021-37371 | Cri | 0.64 | 9.8 | 0.02 | Oct 26, 2021 | Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php. |
- risk 0.64cvss 9.8epss 0.06
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an…
- risk 0.64cvss 9.8epss 0.03
PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database…
- risk 0.64cvss 9.8epss 0.06
Hitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data source and thus retrieve data from the related databases, as demonstrated by an api/repos/dashboards/editor URI.
- risk 0.64cvss 9.8epss 0.01
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
- risk 0.64cvss 9.8epss 0.01
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
- risk 0.64cvss 9.8epss 0.01
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.
- risk 0.64cvss 9.8epss 0.08
A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to…
- risk 0.64cvss 9.8epss 0.05
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a…
- risk 0.64cvss 9.8epss 0.05
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
- risk 0.64cvss 9.8epss 0.02
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.
- risk 0.64cvss 9.8epss 0.01
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.
- risk 0.64cvss 9.8epss 0.01
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
- risk 0.64cvss 9.8epss 0.02
Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.