CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 144 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36033 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php. | ||
| CVE-2021-26232 | Cri | 0.64 | 9.8 | 0.03 | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php. | ||
| CVE-2021-26231 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php. | ||
| CVE-2021-26229 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php. | ||
| CVE-2021-26228 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php. | ||
| CVE-2021-26765 | Cri | 0.64 | 9.8 | 0.03 | Jul 22, 2021 | SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php. | ||
| CVE-2020-35427 | Cri | 0.64 | 9.8 | 0.03 | Jul 20, 2021 | SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | ||
| CVE-2020-18144 | Cri | 0.64 | 9.8 | 0.01 | Jul 14, 2021 | SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php. | ||
| CVE-2021-33578 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2021 | Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data. | ||
| CVE-2021-24385 | Cri | 0.64 | 9.8 | 0.03 | Jul 12, 2021 | The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL… | ||
| CVE-2020-18544 | Cri | 0.64 | 9.8 | 0.02 | Jul 12, 2021 | SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php". | ||
| CVE-2020-21133 | Cri | 0.64 | 9.8 | 0.02 | Jul 12, 2021 | SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid. | ||
| CVE-2020-21132 | Cri | 0.64 | 9.8 | 0.02 | Jul 12, 2021 | SQL Injection vulnerability in Metinfo 7.0.0beta in index.php. | ||
| CVE-2021-24007 | Cri | 0.64 | 9.8 | 0.01 | Jul 9, 2021 | Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | ||
| CVE-2020-23711 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2021 | SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php. | ||
| CVE-2021-35456 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2021 | Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload | ||
| CVE-2021-35048 | Cri | 0.64 | 9.8 | 0.01 | Jun 25, 2021 | Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and… | ||
| CVE-2020-18667 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn. | ||
| CVE-2020-20392 | Cri | 0.64 | 9.8 | 0.01 | Jun 23, 2021 | SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. | ||
| CVE-2021-24361 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2021 | In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues. |
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
- risk 0.64cvss 9.8epss 0.01
SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.
- risk 0.64cvss 9.8epss 0.01
Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data.
- risk 0.64cvss 9.8epss 0.03
The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL…
- risk 0.64cvss 9.8epss 0.02
SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
- risk 0.64cvss 9.8epss 0.01
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
- risk 0.64cvss 9.8epss 0.02
Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload
- risk 0.64cvss 9.8epss 0.01
Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in WebPort <=1.19.1 via the new connection, parameter name in type-conn.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
- risk 0.64cvss 9.8epss 0.02
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.