CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 142 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-20675 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2021 | Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/. | ||
| CVE-2020-19705 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2021 | thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add. | ||
| CVE-2021-36385 | Cri | 0.64 | 9.8 | 0.03 | Aug 24, 2021 | A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell. | ||
| CVE-2021-24551 | Cri | 0.64 | 9.8 | 0.02 | Aug 23, 2021 | The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue | ||
| CVE-2021-39302 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2021 | MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value. | ||
| CVE-2021-37358 | Cri | 0.64 | 9.8 | 0.02 | Aug 18, 2021 | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=". | ||
| CVE-2020-18164 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2021 | SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter. | ||
| CVE-2021-38754 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2021 | SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php. | ||
| CVE-2021-38302 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2021 | The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection. | ||
| CVE-2021-36789 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. | ||
| CVE-2021-28890 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2021 | J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, related to the use of ${} to join SQL statements. | |
| CVE-2021-37599 | Cri | 0.64 | 9.8 | 0.03 | Aug 12, 2021 | The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter. | ||
| CVE-2020-20975 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2021 | In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter. | ||
| CVE-2021-38574 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2021 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string. | ||
| CVE-2021-38167 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication. | ||
| CVE-2021-38159 | Cri | 0.64 | 9.8 | 0.02 | Aug 7, 2021 | In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL… | ||
| CVE-2021-36351 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2021 | SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php. | ||
| CVE-2021-32590 | Cri | 0.64 | 9.9 | 0.02 | Aug 4, 2021 | Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on… | ||
| CVE-2021-37558 | Cri | 0.64 | 9.8 | 0.02 | Aug 3, 2021 | A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a… | ||
| CVE-2021-37832 | Cri | 0.64 | 9.8 | 0.04 | Aug 3, 2021 | A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter. |
- risk 0.64cvss 9.8epss 0.01
Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.
- risk 0.64cvss 9.8epss 0.01
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
- risk 0.64cvss 9.8epss 0.03
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.
- risk 0.64cvss 9.8epss 0.02
The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter before using it in a SQL statement, leading to a SQL injection issue
- risk 0.64cvss 9.8epss 0.01
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
- risk 0.64cvss 9.8epss 0.02
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checkrepeat&v_name=".
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
- risk 0.64cvss 9.8epss 0.01
The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, related to the use of ${} to join SQL statements.
- risk 0.64cvss 9.8epss 0.03
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword parameter.
- risk 0.64cvss 9.8epss 0.01
In \lib\admin\action\dataaction.class.php in Gxlcms v1.1, SQL Injection exists via the $filename parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the end of a string.
- risk 0.64cvss 9.8epss 0.01
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.
- risk 0.64cvss 9.8epss 0.02
In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL…
- risk 0.64cvss 9.8epss 0.02
SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php.
- risk 0.64cvss 9.9epss 0.02
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on…
- risk 0.64cvss 9.8epss 0.02
A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a…
- risk 0.64cvss 9.8epss 0.04
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.