CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 171 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-18789 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. | ||
| CVE-2018-18787 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. | ||
| CVE-2018-18786 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | ||
| CVE-2018-18785 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. | ||
| CVE-2018-18705 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php. | ||
| CVE-2018-18704 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter. | ||
| CVE-2018-18702 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. | ||
| CVE-2016-10731 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status,… | ||
| CVE-2018-17446 | Cri | 0.64 | 9.8 | 0.02 | Oct 23, 2018 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | ||
| CVE-2018-18530 | Cri | 0.64 | 9.8 | 0.01 | Oct 19, 2018 | ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI. | ||
| CVE-2018-18529 | Cri | 0.64 | 9.8 | 0.01 | Oct 19, 2018 | ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI. | ||
| CVE-2018-18527 | Cri | 0.64 | 9.8 | 0.02 | Oct 19, 2018 | OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter. | ||
| CVE-2018-18488 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2018 | In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter. | ||
| CVE-2018-18486 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2018 | An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter. | ||
| CVE-2018-18450 | Cri | 0.64 | 9.8 | 0.02 | Oct 17, 2018 | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI. | ||
| CVE-2018-18427 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2018 | s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php. | ||
| CVE-2018-18242 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2018 | youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86. | ||
| CVE-2018-18200 | Cri | 0.64 | 9.8 | 0.01 | Oct 9, 2018 | There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4. | ||
| CVE-2018-18084 | Cri | 0.64 | 9.8 | 0.01 | Oct 9, 2018 | An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter. | ||
| CVE-2018-18075 | Cri | 0.64 | 9.8 | 0.02 | Oct 9, 2018 | WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter. |
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
- risk 0.64cvss 9.8epss 0.02
PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php.
- risk 0.64cvss 9.8epss 0.02
PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
- risk 0.64cvss 9.8epss 0.01
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.
- risk 0.64cvss 9.8epss 0.01
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status,…
- risk 0.64cvss 9.8epss 0.02
A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
- risk 0.64cvss 9.8epss 0.01
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.
- risk 0.64cvss 9.8epss 0.01
ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.
- risk 0.64cvss 9.8epss 0.02
OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.
- risk 0.64cvss 9.8epss 0.01
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.
- risk 0.64cvss 9.8epss 0.02
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI.
- risk 0.64cvss 9.8epss 0.01
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
- risk 0.64cvss 9.8epss 0.01
youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.
- risk 0.64cvss 9.8epss 0.01
There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
- risk 0.64cvss 9.8epss 0.02
WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.