CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 175 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11722 | Cri | 0.64 | 9.8 | 0.02 | Jun 5, 2018 | WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded. | ||
| CVE-2016-10553 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier. | ||
| CVE-2016-10550 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements.… | ||
| CVE-2018-11140 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2018 | The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type). | ||
| CVE-2018-11136 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2018 | The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type). | ||
| CVE-2015-9244 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection. | ||
| CVE-2018-11528 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. | ||
| CVE-2018-11309 | Cri | 0.64 | 9.8 | 0.02 | May 28, 2018 | Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request. | ||
| CVE-2018-11515 | Cri | 0.64 | 9.8 | 0.02 | May 28, 2018 | The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. | ||
| CVE-2018-11373 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2018 | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. | ||
| CVE-2018-11372 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2018 | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. | ||
| CVE-2018-11369 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2018 | An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter. | ||
| CVE-2018-10759 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2018 | PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter. | ||
| CVE-2018-11032 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2018 | PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function. | ||
| CVE-2018-8824 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2018 | modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter. | ||
| CVE-2017-17902 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2018 | SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI. | ||
| CVE-2018-10284 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2018 | Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter. | ||
| CVE-2018-10283 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2018 | CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action. | ||
| CVE-2018-1290 | Cri | 0.64 | 9.8 | 0.03 | Apr 20, 2018 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like retrieveAuditEntries of AuditsApiResource Class and… | ||
| CVE-2018-10225 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2018 | thinkphp 3.1.3 has SQL Injection via the index.php s parameter. |
- risk 0.64cvss 9.8epss 0.02
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
- risk 0.64cvss 9.8epss 0.01
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier.
- risk 0.64cvss 9.8epss 0.02
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements.…
- risk 0.64cvss 9.8epss 0.01
The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type).
- risk 0.64cvss 9.8epss 0.01
The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type).
- risk 0.64cvss 9.8epss 0.02
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
- risk 0.64cvss 9.8epss 0.02
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
- risk 0.64cvss 9.8epss 0.02
Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request.
- risk 0.64cvss 9.8epss 0.02
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
- risk 0.64cvss 9.8epss 0.01
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
- risk 0.64cvss 9.8epss 0.01
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
- risk 0.64cvss 9.8epss 0.02
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.
- risk 0.64cvss 9.8epss 0.01
PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function.
- risk 0.64cvss 9.8epss 0.01
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter.
- risk 0.64cvss 9.8epss 0.01
SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI.
- risk 0.64cvss 9.8epss 0.01
Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.
- risk 0.64cvss 9.8epss 0.01
CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.
- risk 0.64cvss 9.8epss 0.03
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like retrieveAuditEntries of AuditsApiResource Class and…
- risk 0.64cvss 9.8epss 0.01
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.