CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 169 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20716 | Cri | 0.64 | 9.8 | 0.01 | Jan 15, 2019 | CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature. | ||
| CVE-2018-20715 | Cri | 0.64 | 9.8 | 0.01 | Jan 15, 2019 | The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php. | ||
| CVE-2019-6296 | Cri | 0.64 | 9.8 | 0.01 | Jan 15, 2019 | Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter. | ||
| CVE-2019-6295 | Cri | 0.64 | 9.8 | 0.01 | Jan 15, 2019 | Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter. | ||
| CVE-2019-6259 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2019 | An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter. | ||
| CVE-2018-16803 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2019 | In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code. | ||
| CVE-2018-16188 | Cri | 0.64 | 9.8 | 0.02 | Jan 9, 2019 | SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions… | ||
| CVE-2019-5720 | Cri | 0.64 | 9.8 | 0.02 | Jan 8, 2019 | includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter. | ||
| CVE-2018-19415 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2019 | Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to join_group.php or (2) comment_id parameter to story.php. | ||
| CVE-2019-3577 | Cri | 0.64 | 9.8 | 0.01 | Jan 2, 2019 | An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI. | ||
| CVE-2019-3576 | Cri | 0.64 | 9.8 | 0.02 | Jan 2, 2019 | inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveorite/ PATH_INFO. The vulnerable code location is com.inxedu.os.edu.controller.user.UserController#deleteFavorite (aka deleteFavorite in… | ||
| CVE-2018-20572 | Cri | 0.64 | 9.8 | 0.02 | Dec 28, 2018 | WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893. | ||
| CVE-2018-20569 | Cri | 0.64 | 9.8 | 0.02 | Dec 28, 2018 | user/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass. | ||
| CVE-2018-20568 | Cri | 0.64 | 9.8 | 0.02 | Dec 28, 2018 | Administrator/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass. | ||
| CVE-2018-1000631 | Cri | 0.64 | 9.8 | 0.02 | Dec 28, 2018 | Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tmx/TmxCtl/src/lib/PluginStatus.cpp and TmxControl::user_info() function, which could allow the attacker to view, add, modify or delete information in the… | ||
| CVE-2018-20508 | Cri | 0.64 | 9.8 | 0.01 | Dec 27, 2018 | CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function. | ||
| CVE-2018-20480 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter. | ||
| CVE-2018-20479 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2018 | An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter. | ||
| CVE-2018-20477 | Cri | 0.64 | 9.8 | 0.01 | Dec 26, 2018 | An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field. | ||
| CVE-2018-18399 | Cri | 0.64 | 9.8 | 0.03 | Dec 20, 2018 | SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter. |
- risk 0.64cvss 9.8epss 0.01
CubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
- risk 0.64cvss 9.8epss 0.01
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php.
- risk 0.64cvss 9.8epss 0.01
Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter.
- risk 0.64cvss 9.8epss 0.01
Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter.
- risk 0.64cvss 9.8epss 0.02
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.
- risk 0.64cvss 9.8epss 0.02
SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions…
- risk 0.64cvss 9.8epss 0.02
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via the void_transaction.php filterType parameter.
- risk 0.64cvss 9.8epss 0.01
Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to join_group.php or (2) comment_id parameter to story.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI.
- risk 0.64cvss 9.8epss 0.02
inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveorite/ PATH_INFO. The vulnerable code location is com.inxedu.os.edu.controller.user.UserController#deleteFavorite (aka deleteFavorite in…
- risk 0.64cvss 9.8epss 0.02
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.
- risk 0.64cvss 9.8epss 0.02
user/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass.
- risk 0.64cvss 9.8epss 0.02
Administrator/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass.
- risk 0.64cvss 9.8epss 0.02
Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tmx/TmxCtl/src/lib/PluginStatus.cpp and TmxControl::user_info() function, which could allow the attacker to view, add, modify or delete information in the…
- risk 0.64cvss 9.8epss 0.01
CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.