CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 141 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40674 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2021 | An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php. | ||
| CVE-2021-24741 | Cri | 0.64 | 9.8 | 0.06 | Sep 20, 2021 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable… | ||
| CVE-2021-40670 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2021 | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file. | ||
| CVE-2021-40669 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2021 | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file. | ||
| CVE-2020-21127 | Cri | 0.64 | 9.8 | 0.02 | Sep 15, 2021 | MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel. | ||
| CVE-2020-21121 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2021 | Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file. | ||
| CVE-2021-38833 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2021 | SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE. | ||
| CVE-2021-37422 | Cri | 0.64 | 9.8 | 0.03 | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. | ||
| CVE-2021-38727 | Cri | 0.64 | 9.8 | 0.02 | Sep 9, 2021 | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items | ||
| CVE-2021-40814 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2021 | The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection. | ||
| CVE-2020-19853 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2021 | BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. | ||
| CVE-2021-38840 | Cri | 0.64 | 9.8 | 0.03 | Sep 7, 2021 | SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter. | ||
| CVE-2021-39379 | Cri | 0.64 | 9.8 | 0.04 | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter. | ||
| CVE-2021-39377 | Cri | 0.64 | 9.8 | 0.04 | Sep 1, 2021 | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter. | ||
| CVE-2021-40353 | Cri | 0.64 | 9.8 | 0.03 | Sep 1, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for… | ||
| CVE-2021-38145 | Cri | 0.64 | 9.8 | 0.02 | Aug 31, 2021 | An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&e… | ||
| CVE-2021-38391 | Cri | 0.64 | 9.8 | 0.03 | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of… | ||
| CVE-2021-32983 | Cri | 0.64 | 9.8 | 0.04 | Aug 30, 2021 | A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part… | ||
| CVE-2021-37749 | Cri | 0.64 | 9.8 | 0.02 | Aug 30, 2021 | MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method. | ||
| CVE-2020-18106 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2021 | The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection. |
- risk 0.64cvss 9.8epss 0.01
An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.
- risk 0.64cvss 9.8epss 0.06
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.
- risk 0.64cvss 9.8epss 0.02
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
- risk 0.64cvss 9.8epss 0.01
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
- risk 0.64cvss 9.8epss 0.02
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
- risk 0.64cvss 9.8epss 0.01
The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.
- risk 0.64cvss 9.8epss 0.01
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
- risk 0.64cvss 9.8epss 0.03
SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.
- risk 0.64cvss 9.8epss 0.04
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the ResetUserInfo.php password_stn_id parameter.
- risk 0.64cvss 9.8epss 0.04
A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQL commands to the MySQL (MariaDB) database through the index.php username parameter.
- risk 0.64cvss 9.8epss 0.03
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the index.php USERNAME parameter. NOTE: this issue may exist because of an incomplete fix for…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&e…
- risk 0.64cvss 9.8epss 0.03
A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type before using it as part of…
- risk 0.64cvss 9.8epss 0.04
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part…
- risk 0.64cvss 9.8epss 0.02
MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (within sourceItems) parameter to the GetMap method.
- risk 0.64cvss 9.8epss 0.01
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.