CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 168 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9047 | Cri | 0.64 | 9.8 | 0.02 | Feb 23, 2019 | GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled. | ||
| CVE-2019-8979 | Cri | 0.64 | 9.8 | 0.03 | Feb 21, 2019 | Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. | ||
| CVE-2019-8423 | Cri | 0.64 | 9.8 | 0.02 | Feb 18, 2019 | ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter. | ||
| CVE-2019-8393 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2019 | Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled. | ||
| CVE-2019-8360 | Cri | 0.64 | 9.8 | 0.02 | Feb 16, 2019 | Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter. | ||
| CVE-2015-4615 | Cri | 0.64 | 9.8 | 0.02 | Feb 15, 2019 | Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables | ||
| CVE-2018-20779 | Cri | 0.64 | 9.8 | 0.02 | Feb 11, 2019 | Traq 3.7.1 allows SQL Injection via a tickets?search= URI. | ||
| CVE-2018-20770 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2019 | An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection. | ||
| CVE-2018-13792 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2019 | Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter. | ||
| CVE-2019-7587 | Cri | 0.64 | 9.8 | 0.02 | Feb 7, 2019 | Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function. | ||
| CVE-2019-7585 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2019 | An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public&a=checkemail URI. | ||
| CVE-2019-7568 | Cri | 0.64 | 9.8 | 0.02 | Feb 7, 2019 | An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request. | ||
| CVE-2019-6523 | Cri | 0.64 | 9.8 | 0.02 | Feb 5, 2019 | WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands. | ||
| CVE-2018-4056 | Cri | 0.64 | 9.8 | 0.03 | Feb 5, 2019 | An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN… | ||
| CVE-2019-1000023 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2019 | OPT/NET BV OPTOSS Next Gen Network Management System (NG-NetMS) version v3.6-2 and earlier versions contains a SQL Injection vulnerability in Identified vulnerable parameters: id, id_access_type and id_attr_access that can result in a malicious attacker can include own SQL… | ||
| CVE-2016-1000271 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2019 | Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server. | ||
| CVE-2019-7316 | Cri | 0.64 | 9.8 | 0.03 | Feb 4, 2019 | An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability. | ||
| CVE-2019-6798 | Cri | 0.64 | 9.8 | 0.03 | Jan 26, 2019 | An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature. | ||
| CVE-2019-6805 | Cri | 0.64 | 9.8 | 0.01 | Jan 25, 2019 | SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter. | ||
| CVE-2019-6497 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2019 | Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter. |
- risk 0.64cvss 9.8epss 0.02
GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.
- risk 0.64cvss 9.8epss 0.03
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.
- risk 0.64cvss 9.8epss 0.02
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
- risk 0.64cvss 9.8epss 0.01
Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.
- risk 0.64cvss 9.8epss 0.02
Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
- risk 0.64cvss 9.8epss 0.02
Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables
- risk 0.64cvss 9.8epss 0.02
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter.
- risk 0.64cvss 9.8epss 0.02
Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public&a=checkemail URI.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request.
- risk 0.64cvss 9.8epss 0.02
WebAccess/SCADA, Version 8.3. The software does not properly sanitize its inputs for SQL commands.
- risk 0.64cvss 9.8epss 0.03
An exploitable SQL injection vulnerability exists in the administrator web portal function of coTURN prior to version 4.5.0.9. A login message with a specially crafted username can cause an SQL injection, resulting in authentication bypass, which could give access to the TURN…
- risk 0.64cvss 9.8epss 0.02
OPT/NET BV OPTOSS Next Gen Network Management System (NG-NetMS) version v3.6-2 and earlier versions contains a SQL Injection vulnerability in Identified vulnerable parameters: id, id_access_type and id_attr_access that can result in a malicious attacker can include own SQL…
- risk 0.64cvss 9.8epss 0.02
Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web server.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injection attack through the designer feature.
- risk 0.64cvss 9.8epss 0.01
SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.
- risk 0.64cvss 9.8epss 0.01
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.