CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 18 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17641 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. | ||
| CVE-2017-17640 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | ||
| CVE-2017-17639 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | ||
| CVE-2017-17638 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. | ||
| CVE-2017-17637 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | ||
| CVE-2017-17636 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | ||
| CVE-2017-17635 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. | ||
| CVE-2017-17634 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | ||
| CVE-2017-17633 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter. | ||
| CVE-2017-17632 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | ||
| CVE-2017-17631 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | ||
| CVE-2017-17630 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Yoga Class Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17629 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | ||
| CVE-2017-17628 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | ||
| CVE-2017-17627 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. | ||
| CVE-2017-17626 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. | ||
| CVE-2017-17625 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Professional Service Script 1.0 has SQL Injection via the service-list city parameter. | ||
| CVE-2017-17624 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. | ||
| CVE-2017-17623 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | ||
| CVE-2017-17622 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. |
- risk 0.67cvss 9.8epss 0.02
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
- risk 0.67cvss 9.8epss 0.02
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
- risk 0.67cvss 9.8epss 0.02
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
- risk 0.67cvss 9.8epss 0.02
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
- risk 0.67cvss 9.8epss 0.02
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
- risk 0.67cvss 9.8epss 0.02
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
- risk 0.67cvss 9.8epss 0.02
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.
- risk 0.67cvss 9.8epss 0.02
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
- risk 0.67cvss 9.8epss 0.02
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
- risk 0.67cvss 9.8epss 0.02
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
- risk 0.67cvss 9.8epss 0.02
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
- risk 0.67cvss 9.8epss 0.02
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.02
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.
- risk 0.67cvss 9.8epss 0.02
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
- risk 0.67cvss 9.8epss 0.02
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
- risk 0.67cvss 9.8epss 0.03
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
- risk 0.67cvss 9.8epss 0.03
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
- risk 0.67cvss 9.8epss 0.03
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
- risk 0.67cvss 9.8epss 0.04
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.