CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 17 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-5986 | Cri | 0.67 | 9.8 | 0.03 | Jan 24, 2018 | SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php. | ||
| CVE-2018-5984 | Cri | 0.67 | 9.8 | 0.03 | Jan 24, 2018 | SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI. | ||
| CVE-2018-5978 | Cri | 0.67 | 9.8 | 0.03 | Jan 24, 2018 | SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field. | ||
| CVE-2018-5977 | Cri | 0.67 | 9.8 | 0.02 | Jan 24, 2018 | SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request. | ||
| CVE-2017-17999 | Cri | 0.67 | 9.8 | 0.03 | Jan 23, 2018 | SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/. | ||
| CVE-2018-5315 | Cri | 0.67 | 9.8 | 0.05 | Jan 12, 2018 | The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php. | ||
| CVE-2017-17970 | Cri | 0.67 | 9.8 | 0.05 | Jan 12, 2018 | Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to… | ||
| CVE-2018-5211 | Cri | 0.67 | 9.8 | 0.02 | Jan 9, 2018 | PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. | ||
| CVE-2017-16716 | Cri | 0.67 | 9.8 | 0.06 | Jan 5, 2018 | A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands. | ||
| CVE-2017-17875 | Cri | 0.67 | 9.8 | 0.03 | Dec 27, 2017 | The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action. | ||
| CVE-2017-17873 | Cri | 0.67 | 9.8 | 0.03 | Dec 27, 2017 | Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI. | ||
| CVE-2017-17872 | Cri | 0.67 | 9.8 | 0.03 | Dec 27, 2017 | The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action. | ||
| CVE-2017-17871 | Cri | 0.67 | 9.8 | 0.03 | Dec 27, 2017 | The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter. | ||
| CVE-2017-17870 | Cri | 0.67 | 9.8 | 0.03 | Dec 27, 2017 | The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action. | ||
| CVE-2017-17721 | Cri | 0.67 | 9.8 | 0.04 | Dec 18, 2017 | CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter. | ||
| CVE-2017-17651 | Cri | 0.67 | 9.8 | 0.03 | Dec 18, 2017 | Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter. | ||
| CVE-2017-17645 | Cri | 0.67 | 9.8 | 0.03 | Dec 18, 2017 | Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. | ||
| CVE-2017-17643 | Cri | 0.67 | 9.8 | 0.03 | Dec 18, 2017 | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. | ||
| CVE-2017-17648 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. | ||
| CVE-2017-17642 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. |
- risk 0.67cvss 9.8epss 0.03
SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.
- risk 0.67cvss 9.8epss 0.03
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.
- risk 0.67cvss 9.8epss 0.03
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
- risk 0.67cvss 9.8epss 0.02
SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request.
- risk 0.67cvss 9.8epss 0.03
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.
- risk 0.67cvss 9.8epss 0.05
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
- risk 0.67cvss 9.8epss 0.05
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to…
- risk 0.67cvss 9.8epss 0.02
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
- risk 0.67cvss 9.8epss 0.06
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.
- risk 0.67cvss 9.8epss 0.03
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
- risk 0.67cvss 9.8epss 0.03
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
- risk 0.67cvss 9.8epss 0.03
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
- risk 0.67cvss 9.8epss 0.03
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
- risk 0.67cvss 9.8epss 0.03
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
- risk 0.67cvss 9.8epss 0.04
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
- risk 0.67cvss 9.8epss 0.03
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
- risk 0.67cvss 9.8epss 0.03
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
- risk 0.67cvss 9.8epss 0.03
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
- risk 0.67cvss 9.8epss 0.04
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
- risk 0.67cvss 9.8epss 0.02
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.