CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 151 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19876 | Cri | 0.64 | 9.8 | 0.01 | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006. | ||
| CVE-2020-28994 | Cri | 0.64 | 9.8 | 0.01 | Nov 24, 2020 | A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database. | ||
| CVE-2020-25475 | Cri | 0.64 | 9.8 | 0.01 | Nov 24, 2020 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action. | ||
| CVE-2020-25839 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2020 | NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1. | ||
| CVE-2020-28183 | Cri | 0.64 | 9.8 | 0.03 | Nov 17, 2020 | SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php. | ||
| CVE-2020-28133 | Cri | 0.64 | 9.8 | 0.02 | Nov 17, 2020 | An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php. | ||
| CVE-2020-28138 | Cri | 0.64 | 9.8 | 0.02 | Nov 17, 2020 | SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php. | ||
| CVE-2020-25952 | Cri | 0.64 | 9.8 | 0.04 | Nov 16, 2020 | SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | ||
| CVE-2020-13877 | Cri | 0.64 | 9.8 | 0.02 | Nov 12, 2020 | SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure. | ||
| CVE-2020-27886 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2020 | An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/functions.php file (which is called by login.php). | ||
| CVE-2020-27995 | Cri | 0.64 | 9.8 | 0.09 | Oct 29, 2020 | SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter. | ||
| CVE-2020-26944 | Cri | 0.64 | 9.8 | 0.01 | Oct 16, 2020 | An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely. | ||
| CVE-2020-25273 | Cri | 0.64 | 9.8 | 0.02 | Oct 8, 2020 | In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection. | ||
| CVE-2020-26518 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2020 | Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter. | ||
| CVE-2020-15533 | Cri | 0.64 | 9.8 | 0.04 | Oct 1, 2020 | In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack. | ||
| CVE-2020-25990 | Cri | 0.64 | 9.8 | 0.02 | Oct 1, 2020 | WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. | ||
| CVE-2020-12870 | Cri | 0.64 | 9.8 | 0.02 | Sep 30, 2020 | RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page. | ||
| CVE-2020-26042 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2020 | An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php | ||
| CVE-2020-20800 | Cri | 0.64 | 9.8 | 0.02 | Sep 30, 2020 | An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI. | ||
| CVE-2020-15487 | Cri | 0.64 | 9.8 | 0.04 | Sep 30, 2020 | Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote… |
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.
- risk 0.64cvss 9.8epss 0.01
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
- risk 0.64cvss 9.8epss 0.01
NetIQ Identity Manager 4.8 prior to version 4.8 SP2 HF1 are affected by an injection vulnerability. This vulnerability is fixed in NetIQ IdM 4.8 SP2 HF1.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.
- risk 0.64cvss 9.8epss 0.02
SourceCodester Online Clothing Store 1.0 is affected by a SQL Injection via the txtUserName parameter to login.php.
- risk 0.64cvss 9.8epss 0.04
SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
- risk 0.64cvss 9.8epss 0.02
SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available function of the includes/functions.php file (which is called by login.php).
- risk 0.64cvss 9.8epss 0.09
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely.
- risk 0.64cvss 9.8epss 0.02
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
- risk 0.64cvss 9.8epss 0.02
Artica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php session_id parameter.
- risk 0.64cvss 9.8epss 0.04
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
- risk 0.64cvss 9.8epss 0.02
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
- risk 0.64cvss 9.8epss 0.02
RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Hoosk CMS v1.8.0. There is a SQL injection vulnerability in install/index.php
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.
- risk 0.64cvss 9.8epss 0.04
Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET parameter, it is possible to execute arbitrary SQL statements via a crafted URL. Unauthenticated remote…