CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 167 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-11362 | Cri | 0.64 | 9.8 | 0.02 | Apr 20, 2019 | app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as demonstrated by the /do/reward/3 URI. | ||
| CVE-2018-18018 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2019 | SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter. | ||
| CVE-2019-4012 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2019 | IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:… | ||
| CVE-2019-11196 | Cri | 0.64 | 9.8 | 0.06 | Apr 12, 2019 | An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers… | ||
| CVE-2019-5715 | Cri | 0.64 | 9.8 | 0.02 | Apr 11, 2019 | All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject. | ||
| CVE-2019-7001 | Cri | 0.64 | 9.9 | 0.01 | Apr 4, 2019 | A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior… | ||
| CVE-2019-6506 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2019 | SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection. | ||
| CVE-2019-10708 | Cri | 0.64 | 9.8 | 0.03 | Apr 2, 2019 | S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter. | ||
| CVE-2019-10707 | Cri | 0.64 | 9.8 | 0.01 | Apr 2, 2019 | MKCMS V5.0 has SQL injection via the bplay.php play parameter. | ||
| CVE-2019-9759 | Cri | 0.64 | 9.8 | 0.01 | Apr 2, 2019 | An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/approve_center/list/input_form/work_handle.php run_id parameter. | ||
| CVE-2019-10262 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2019 | A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes. | ||
| CVE-2019-9165 | Cri | 0.64 | 9.8 | 0.05 | Mar 28, 2019 | SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id. | ||
| CVE-2019-9762 | Cri | 0.64 | 9.8 | 0.06 | Mar 14, 2019 | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication. | ||
| CVE-2018-17988 | Cri | 0.64 | 9.8 | 0.02 | Mar 7, 2019 | LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter. | ||
| CVE-2018-17412 | Cri | 0.64 | 9.8 | 0.02 | Mar 7, 2019 | zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header. | ||
| CVE-2018-16809 | Cri | 0.64 | 9.8 | 0.02 | Mar 7, 2019 | An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit. | ||
| CVE-2019-9626 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2019 | PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. | ||
| CVE-2019-9594 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2019 | BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. | ||
| CVE-2019-4032 | Cri | 0.64 | 9.8 | 0.02 | Mar 5, 2019 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM… | ||
| CVE-2019-9566 | Cri | 0.64 | 9.8 | 0.02 | Mar 4, 2019 | FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request. |
- risk 0.64cvss 9.8epss 0.02
app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as demonstrated by the /do/reward/3 URI.
- risk 0.64cvss 9.8epss 0.02
SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slideshow-galleries&method=save Gallery[id] or Gallery[title] parameter.
- risk 0.64cvss 9.8epss 0.02
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID:…
- risk 0.64cvss 9.8epss 0.06
An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers…
- risk 0.64cvss 9.8epss 0.02
All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.
- risk 0.64cvss 9.9epss 0.01
A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior…
- risk 0.64cvss 9.8epss 0.02
SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
- risk 0.64cvss 9.8epss 0.03
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
- risk 0.64cvss 9.8epss 0.01
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/approve_center/list/input_form/work_handle.php run_id parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes.
- risk 0.64cvss 9.8epss 0.05
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
- risk 0.64cvss 9.8epss 0.06
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication.
- risk 0.64cvss 9.8epss 0.02
LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.
- risk 0.64cvss 9.8epss 0.02
zzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.
- risk 0.64cvss 9.8epss 0.01
PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.
- risk 0.64cvss 9.8epss 0.01
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
- risk 0.64cvss 9.8epss 0.02
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM…
- risk 0.64cvss 9.8epss 0.02
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.