CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 150 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13968 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2020 | CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter. | ||
| CVE-2020-24673 | Cri | 0.64 | 9.8 | 0.01 | Dec 22, 2020 | In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file… | ||
| CVE-2020-11717 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2020 | An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities. | ||
| CVE-2020-21378 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2020 | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php. | ||
| CVE-2020-21377 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2020 | SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter. | ||
| CVE-2020-35276 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2020 | EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user. | ||
| CVE-2020-20300 | Cri | 0.64 | 9.8 | 0.09 | Dec 18, 2020 | SQL injection vulnerability in the wp_where function in WeiPHP 5.0. | ||
| CVE-2020-35545 | Cri | 0.64 | 9.8 | 0.04 | Dec 17, 2020 | Time-based SQL injection exists in Spotweb 1.4.9 via the query string. | ||
| CVE-2020-20189 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2020 | SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php. | ||
| CVE-2020-35378 | Cri | 0.64 | 9.8 | 0.02 | Dec 14, 2020 | SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields. | ||
| CVE-2020-19165 | Cri | 0.64 | 9.8 | 0.02 | Dec 11, 2020 | PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter. | ||
| CVE-2020-25889 | Cri | 0.64 | 9.8 | 0.03 | Dec 8, 2020 | Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege. | ||
| CVE-2020-29288 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2020 | An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable. | ||
| CVE-2020-29287 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2020 | An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php. | ||
| CVE-2020-29285 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2020 | SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php. | ||
| CVE-2020-29284 | Cri | 0.64 | 9.8 | 0.06 | Dec 2, 2020 | The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id… | ||
| CVE-2020-29283 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2020 | An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php. | ||
| CVE-2020-29282 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2020 | SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. | ||
| CVE-2020-29280 | Cri | 0.64 | 9.8 | 0.02 | Dec 2, 2020 | The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. | ||
| CVE-2020-6880 | Cri | 0.64 | 9.8 | 0.01 | Dec 1, 2020 | A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all… |
- risk 0.64cvss 9.8epss 0.01
CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.
- risk 0.64cvss 9.8epss 0.01
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.
- risk 0.64cvss 9.8epss 0.02
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
- risk 0.64cvss 9.8epss 0.09
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
- risk 0.64cvss 9.8epss 0.04
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
- risk 0.64cvss 9.8epss 0.02
PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.
- risk 0.64cvss 9.8epss 0.03
Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.
- risk 0.64cvss 9.8epss 0.03
An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.
- risk 0.64cvss 9.8epss 0.03
An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.
- risk 0.64cvss 9.8epss 0.06
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id…
- risk 0.64cvss 9.8epss 0.01
An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
- risk 0.64cvss 9.8epss 0.02
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
- risk 0.64cvss 9.8epss 0.01
A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all…