CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 158 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-3583 | Cri | 0.64 | 9.8 | 0.01 | Nov 26, 2019 | It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two… | ||
| CVE-2019-19250 | Cri | 0.64 | 9.8 | 0.01 | Nov 25, 2019 | OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js. | ||
| CVE-2019-19113 | Cri | 0.64 | 9.8 | 0.02 | Nov 18, 2019 | main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection. | ||
| CVE-2011-2936 | Cri | 0.64 | 9.8 | 0.02 | Nov 12, 2019 | Elgg through 1.7.10 has a SQL injection vulnerability | ||
| CVE-2019-12918 | Cri | 0.64 | 9.8 | 0.01 | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir]. | ||
| CVE-2019-18663 | Cri | 0.64 | 9.8 | 0.01 | Nov 4, 2019 | A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter. | ||
| CVE-2019-18662 | Cri | 0.64 | 9.8 | 0.02 | Nov 2, 2019 | An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query.… | ||
| CVE-2013-2738 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2019 | minidlna has SQL Injection that may allow retrieval of arbitrary files | ||
| CVE-2019-18464 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2019 | In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the… | ||
| CVE-2009-4899 | Cri | 0.64 | 9.8 | 0.01 | Oct 28, 2019 | pixelpost 1.7.1 has SQL injection | ||
| CVE-2019-5114 | Cri | 0.64 | 9.9 | 0.01 | Oct 25, 2019 | An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,… | ||
| CVE-2019-18387 | Cri | 0.64 | 9.8 | 0.01 | Oct 23, 2019 | Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details. | ||
| CVE-2019-18344 | Cri | 0.64 | 9.8 | 0.01 | Oct 23, 2019 | Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter). | ||
| CVE-2019-13409 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2019 | A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password. | ||
| CVE-2019-17580 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2019 | tonyy dormsystem through 1.3 allows SQL Injection in admin.php. | ||
| CVE-2019-17553 | Cri | 0.64 | 9.8 | 0.02 | Oct 14, 2019 | An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI. | ||
| CVE-2019-17552 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2019 | An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload. | ||
| CVE-2015-9467 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2019 | The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter. | ||
| CVE-2015-9466 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2019 | The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable. | ||
| CVE-2019-17429 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2019 | Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter. |
- risk 0.64cvss 9.8epss 0.01
It was found that Typo3 Core versions 4.5.0 - 4.5.5 uses prepared statements that, if the parameter values are not properly replaced, could lead to a SQL Injection vulnerability. This issue can only be exploited if two or more parameters are bound to the query and at least two…
- risk 0.64cvss 9.8epss 0.01
OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.
- risk 0.64cvss 9.8epss 0.02
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
- risk 0.64cvss 9.8epss 0.02
Elgg through 1.7.10 has a SQL injection vulnerability
- risk 0.64cvss 9.8epss 0.01
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query.…
- risk 0.64cvss 9.8epss 0.02
minidlna has SQL Injection that may allow retrieval of arbitrary files
- risk 0.64cvss 9.8epss 0.02
In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the…
- risk 0.64cvss 9.8epss 0.01
pixelpost 1.7.1 has SQL injection
- risk 0.64cvss 9.9epss 0.01
An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability,…
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.
- risk 0.64cvss 9.8epss 0.01
tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
- risk 0.64cvss 9.8epss 0.02
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
- risk 0.64cvss 9.8epss 0.02
The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.
- risk 0.64cvss 9.8epss 0.01
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.