CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 165 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13275 | Cri | 0.64 | 9.8 | 0.03 | Jul 4, 2019 | An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection. | ||
| CVE-2019-12850 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168. | ||
| CVE-2017-18346 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter. | ||
| CVE-2019-12960 | Cri | 0.64 | 9.8 | 0.01 | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d. | ||
| CVE-2019-12939 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter. | ||
| CVE-2018-15868 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2019 | SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie. | ||
| CVE-2018-17388 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php. | ||
| CVE-2018-17386 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/. | ||
| CVE-2018-17381 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter. | ||
| CVE-2018-17374 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter. | ||
| CVE-2018-17842 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter. | ||
| CVE-2018-17841 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter. | ||
| CVE-2018-17840 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter. | ||
| CVE-2018-17399 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter. | ||
| CVE-2018-17398 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter. | ||
| CVE-2018-17393 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php. | ||
| CVE-2018-18758 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757. | ||
| CVE-2018-18757 | Cri | 0.64 | 9.8 | 0.02 | Jun 19, 2019 | Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758. | ||
| CVE-2019-12149 | Cri | 0.64 | 9.8 | 0.01 | Jun 11, 2019 | SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands. | ||
| CVE-2018-11801 | Cri | 0.64 | 9.8 | 0.05 | Jun 11, 2019 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table. |
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
- risk 0.64cvss 9.8epss 0.02
A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.
- risk 0.64cvss 9.8epss 0.01
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.
- risk 0.64cvss 9.8epss 0.01
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
- risk 0.64cvss 9.8epss 0.02
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
- risk 0.64cvss 9.8epss 0.02
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
- risk 0.64cvss 9.8epss 0.02
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
- risk 0.64cvss 9.8epss 0.02
Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.
- risk 0.64cvss 9.8epss 0.02
Open Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x before 2.1.2 and silverstripe/registry module 2.1.x before 2.1.1 and 2.2.x before 2.2.1 allows attackers to execute arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.05
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.