CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 20 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17600 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. | ||
| CVE-2017-17599 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. | ||
| CVE-2017-17598 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter. | ||
| CVE-2017-17597 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter. | ||
| CVE-2017-17596 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter. | ||
| CVE-2017-17595 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. | ||
| CVE-2017-17594 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. | ||
| CVE-2017-17592 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter. | ||
| CVE-2017-17591 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | ||
| CVE-2017-17590 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. | ||
| CVE-2017-17589 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter. | ||
| CVE-2017-17588 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter. | ||
| CVE-2017-17587 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter. | ||
| CVE-2017-17586 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter. | ||
| CVE-2017-17585 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter. | ||
| CVE-2017-17584 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. | ||
| CVE-2017-17583 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. | ||
| CVE-2017-17582 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. | ||
| CVE-2017-17581 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. | ||
| CVE-2017-17580 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter. |
- risk 0.67cvss 9.8epss 0.03
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.
- risk 0.67cvss 9.8epss 0.03
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
- risk 0.67cvss 9.8epss 0.03
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
- risk 0.67cvss 9.8epss 0.03
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
- risk 0.67cvss 9.8epss 0.03
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
- risk 0.67cvss 9.8epss 0.03
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
- risk 0.67cvss 9.8epss 0.04
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
- risk 0.67cvss 9.8epss 0.04
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
- risk 0.67cvss 9.8epss 0.03
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.
- risk 0.67cvss 9.8epss 0.03
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.
- risk 0.67cvss 9.8epss 0.03
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.
- risk 0.67cvss 9.8epss 0.03
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
- risk 0.67cvss 9.8epss 0.03
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
- risk 0.67cvss 9.8epss 0.03
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
- risk 0.67cvss 9.8epss 0.03
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
- risk 0.67cvss 9.8epss 0.03
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
- risk 0.67cvss 9.8epss 0.03
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
- risk 0.67cvss 9.8epss 0.03
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.