CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 157 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-6960 | Cri | 0.64 | 9.8 | 0.01 | Jan 22, 2020 | The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6… | ||
| CVE-2016-11018 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2020 | An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback(). | ||
| CVE-2020-7229 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2020 | An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php. | ||
| CVE-2011-2715 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2020 | An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. | ||
| CVE-2011-5020 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2020 | An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011. | ||
| CVE-2014-4984 | Cri | 0.64 | 9.8 | 0.03 | Jan 10, 2020 | Déjà Vu Crescendo Sales CRM has remote SQL Injection | ||
| CVE-2019-4651 | Cri | 0.64 | 9.8 | 0.01 | Jan 9, 2020 | IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962. | ||
| CVE-2011-5266 | Cri | 0.64 | 9.8 | 0.01 | Jan 8, 2020 | Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass. | ||
| CVE-2020-5510 | Cri | 0.64 | 9.8 | 0.02 | Jan 8, 2020 | PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file. | ||
| CVE-2020-5841 | Cri | 0.64 | 9.8 | 0.01 | Jan 7, 2020 | An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication. | ||
| CVE-2019-7478 | Cri | 0.64 | 9.8 | 0.01 | Dec 31, 2019 | A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1. | ||
| CVE-2019-18234 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2019 | Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2019-17527 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2019 | dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter. | ||
| CVE-2019-19846 | Cri | 0.64 | 9.8 | 0.02 | Dec 18, 2019 | In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors. | ||
| CVE-2019-15933 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2019 | Intesync Solismed 3.3sp has SQL Injection. | ||
| CVE-2014-7257 | Cri | 0.64 | 9.8 | 0.02 | Dec 11, 2019 | SQL injection vulnerability in DBD::PgPP 0.05 and earlier | ||
| CVE-2019-19649 | Cri | 0.64 | 9.8 | 0.10 | Dec 11, 2019 | Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function. | ||
| CVE-2013-2745 | Cri | 0.64 | 9.8 | 0.02 | Dec 4, 2019 | An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0 | ||
| CVE-2011-1933 | Cri | 0.64 | 9.8 | 0.02 | Nov 26, 2019 | SQL injection vulnerability in Jifty::DBI before 0.68. | ||
| CVE-2011-3584 | Cri | 0.64 | 9.8 | 0.01 | Nov 26, 2019 | The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input. |
- risk 0.64cvss 9.8epss 0.01
The following versions of MAXPRO VMS and NVR, MAXPRO VMS:HNMSWVMS prior to Version VMS560 Build 595 T2-Patch, HNMSWVMSLT prior to Version VMS560 Build 595 T2-Patch, MAXPRO NVR: MAXPRO NVR XE prior to Version NVR 5.6 Build 595 T2-Patch, MAXPRO NVR SE prior to Version NVR 5.6…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). The file is _lib/class.Job.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.
- risk 0.64cvss 9.8epss 0.03
Déjà Vu Crescendo Sales CRM has remote SQL Injection
- risk 0.64cvss 9.8epss 0.01
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
- risk 0.64cvss 9.8epss 0.01
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
- risk 0.64cvss 9.8epss 0.02
PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.
- risk 0.64cvss 9.8epss 0.02
Equinox Control Expert all versions, is vulnerable to an SQL injection attack, which may allow an attacker to remotely execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter.
- risk 0.64cvss 9.8epss 0.02
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
- risk 0.64cvss 9.8epss 0.02
Intesync Solismed 3.3sp has SQL Injection.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in Jifty::DBI before 0.68.
- risk 0.64cvss 9.8epss 0.01
The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.