CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 212 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0479 | Cri | 0.60 | 9.8 | 0.44 | Mar 28, 2022 | The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site… | ||
| CVE-2021-35042 | Cri | 0.60 | 9.8 | 0.44 | Jul 2, 2021 | Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. | ||
| CVE-2020-13568 | Hig | 0.60 | 8.8 | 0.30 | Apr 13, 2021 | SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST parameter action is “Submit”, the POST parameter… | ||
| CVE-2020-15927 | Hig | 0.60 | 8.8 | 0.41 | Oct 6, 2020 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module. | ||
| CVE-2019-16065 | Hig | 0.60 | 8.8 | 0.03 | Mar 19, 2020 | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL commands to expose and compromise the web server, expose database tables and values, and potentially execute system-based commands as… | ||
| CVE-2015-7567 | Cri | 0.60 | 9.8 | 0.04 | Feb 18, 2020 | SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter. | ||
| CVE-2012-5698 | Hig | 0.60 | 8.8 | 0.02 | Jan 23, 2020 | BabyGekko before 1.2.4 has SQL injection. | ||
| CVE-2019-13462 | Cri | 0.60 | 9.1 | 0.11 | Aug 12, 2019 | Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. | ||
| CVE-2018-12254 | Hig | 0.60 | 8.8 | 0.03 | Jun 12, 2018 | router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI. | ||
| CVE-2018-9250 | Hig | 0.60 | 8.8 | 0.31 | May 18, 2018 | interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter. | ||
| CVE-2018-10256 | Hig | 0.60 | 8.8 | 0.03 | May 1, 2018 | A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query. | ||
| CVE-2018-1282 | Cri | 0.60 | 9.1 | 0.05 | Apr 5, 2018 | This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation. | ||
| CVE-2017-17615 | Hig | 0.60 | 8.8 | 0.02 | Dec 13, 2017 | Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter. | ||
| CVE-2017-15578 | Hig | 0.60 | 8.8 | 0.01 | Oct 18, 2017 | In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php. | ||
| CVE-2017-14848 | Hig | 0.60 | 8.8 | 0.03 | Oct 3, 2017 | WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter. | ||
| CVE-2017-14758 | Hig | 0.60 | 8.8 | 0.03 | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an… | ||
| CVE-2017-14757 | Hig | 0.60 | 8.8 | 0.02 | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to… | ||
| CVE-2017-14847 | Hig | 0.60 | 8.8 | 0.03 | Sep 28, 2017 | Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter. | ||
| CVE-2017-14846 | Hig | 0.60 | 8.8 | 0.03 | Sep 28, 2017 | Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter. | ||
| CVE-2017-14845 | Hig | 0.60 | 8.8 | 0.03 | Sep 28, 2017 | Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter. |
- risk 0.60cvss 9.8epss 0.44
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site…
- risk 0.60cvss 9.8epss 0.44
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
- risk 0.60cvss 8.8epss 0.30
SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST parameter action is “Submit”, the POST parameter…
- risk 0.60cvss 8.8epss 0.41
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
- risk 0.60cvss 8.8epss 0.03
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows an attacker to execute SQL commands to expose and compromise the web server, expose database tables and values, and potentially execute system-based commands as…
- risk 0.60cvss 9.8epss 0.04
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter.
- risk 0.60cvss 8.8epss 0.02
BabyGekko before 1.2.4 has SQL injection.
- risk 0.60cvss 9.1epss 0.11
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
- risk 0.60cvss 8.8epss 0.03
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.
- risk 0.60cvss 8.8epss 0.31
interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.
- risk 0.60cvss 8.8epss 0.03
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.
- risk 0.60cvss 9.1epss 0.05
This vulnerability in Apache Hive JDBC driver 0.7.1 to 2.3.2 allows carefully crafted arguments to be used to bypass the argument escaping/cleanup that JDBC driver does in PreparedStatement implementation.
- risk 0.60cvss 8.8epss 0.02
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
- risk 0.60cvss 8.8epss 0.01
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
- risk 0.60cvss 8.8epss 0.03
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
- risk 0.60cvss 8.8epss 0.03
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an…
- risk 0.60cvss 8.8epss 0.02
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to…
- risk 0.60cvss 8.8epss 0.03
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
- risk 0.60cvss 8.8epss 0.03
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
- risk 0.60cvss 8.8epss 0.03
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.