CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 149 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-20295 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands. | ||
| CVE-2020-20294 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2021 | An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands. | ||
| CVE-2020-20289 | Cri | 0.64 | 9.8 | 0.01 | Feb 1, 2021 | Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability. | ||
| CVE-2021-3286 | Cri | 0.64 | 9.8 | 0.01 | Jan 26, 2021 | SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545. | ||
| CVE-2020-35263 | Cri | 0.64 | 9.8 | 0.02 | Jan 26, 2021 | EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution. | ||
| CVE-2020-23262 | Cri | 0.64 | 9.8 | 0.01 | Jan 26, 2021 | An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do. | ||
| CVE-2021-22851 | Cri | 0.64 | 9.8 | 0.01 | Jan 19, 2021 | HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data. | ||
| CVE-2020-29015 | Cri | 0.64 | 9.8 | 0.03 | Jan 14, 2021 | A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL… | ||
| CVE-2020-26712 | Cri | 0.64 | 9.8 | 0.02 | Jan 12, 2021 | REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability… | ||
| CVE-2021-3118 | Cri | 0.64 | 9.8 | 0.02 | Jan 11, 2021 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The… | ||
| CVE-2021-3021 | Cri | 0.64 | 9.8 | 0.02 | Jan 5, 2021 | ISPConfig before 3.2.2 allows SQL injection. | ||
| CVE-2020-26045 | Cri | 0.64 | 9.8 | 0.02 | Jan 5, 2021 | FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. | ||
| CVE-2020-35245 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser. | ||
| CVE-2020-35244 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup. | ||
| CVE-2020-35243 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb. | ||
| CVE-2020-35242 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2020 | Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory. | ||
| CVE-2020-29474 | Cri | 0.64 | 9.8 | 0.04 | Dec 24, 2020 | EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution. | ||
| CVE-2020-29472 | Cri | 0.64 | 9.8 | 0.04 | Dec 24, 2020 | EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution. | ||
| CVE-2020-28074 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2020 | SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin. | ||
| CVE-2020-28073 | Cri | 0.64 | 9.8 | 0.03 | Dec 23, 2020 | SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system. |
- risk 0.64cvss 9.8epss 0.01
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.02
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.
- risk 0.64cvss 9.8epss 0.02
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
- risk 0.64cvss 9.8epss 0.01
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
- risk 0.64cvss 9.8epss 0.03
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to execute arbitrary SQL queries or commands by sending a request with a crafted Authorization header containing a malicious SQL…
- risk 0.64cvss 9.8epss 0.02
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability…
- risk 0.64cvss 9.8epss 0.02
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The…
- risk 0.64cvss 9.8epss 0.02
ISPConfig before 3.2.2 allows SQL injection.
- risk 0.64cvss 9.8epss 0.02
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
- risk 0.64cvss 9.8epss 0.01
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addUser.
- risk 0.64cvss 9.8epss 0.01
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::addGroup.
- risk 0.64cvss 9.8epss 0.01
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserInfoInDb.
- risk 0.64cvss 9.8epss 0.01
Flamingo (aka FlamingoIM) through 2020-09-29 has a SQL injection vulnerability in UserManager::updateUserTeamInfoInDbAndMemory.
- risk 0.64cvss 9.8epss 0.04
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
- risk 0.64cvss 9.8epss 0.04
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
- risk 0.64cvss 9.8epss 0.02
SourceCodester Online Health Care System 1.0 is affected by SQL Injection which allows a potential attacker to bypass the authentication system and become an admin.
- risk 0.64cvss 9.8epss 0.03
SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system.