CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 19 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17621 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. | ||
| CVE-2017-17620 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. | ||
| CVE-2017-17619 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Laundry Booking Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17618 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. | ||
| CVE-2017-17617 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. | ||
| CVE-2017-17616 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Event Search Script 1.0 has SQL Injection via the /event-list city parameter. | ||
| CVE-2017-17614 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17613 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. | ||
| CVE-2017-17612 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter. | ||
| CVE-2017-17611 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Doctor Search Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17610 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter. | ||
| CVE-2017-17609 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. | ||
| CVE-2017-17608 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Child Care Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17607 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. | ||
| CVE-2017-17606 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17605 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. | ||
| CVE-2017-17604 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. | ||
| CVE-2017-17603 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. | ||
| CVE-2017-17602 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. | ||
| CVE-2017-17601 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter. |
- risk 0.67cvss 9.8epss 0.04
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
- risk 0.67cvss 9.8epss 0.03
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
- risk 0.67cvss 9.8epss 0.04
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
- risk 0.67cvss 9.8epss 0.03
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Food Order Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.
- risk 0.67cvss 9.8epss 0.04
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
- risk 0.67cvss 9.8epss 0.03
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
- risk 0.67cvss 9.8epss 0.03
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Child Care Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
- risk 0.67cvss 9.8epss 0.03
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
- risk 0.67cvss 9.8epss 0.03
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
- risk 0.67cvss 9.8epss 0.03
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
- risk 0.67cvss 9.8epss 0.03
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.