CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 23 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-15967 | Cri | 0.67 | 9.8 | 0.02 | Oct 29, 2017 | Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template. | ||
| CVE-2017-15966 | Cri | 0.67 | 9.8 | 0.03 | Oct 29, 2017 | The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php. | ||
| CVE-2017-15965 | Cri | 0.67 | 9.8 | 0.03 | Oct 29, 2017 | The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. | ||
| CVE-2017-15964 | Cri | 0.67 | 9.8 | 0.02 | Oct 29, 2017 | Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI. | ||
| CVE-2017-15963 | Cri | 0.67 | 9.8 | 0.02 | Oct 29, 2017 | iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter. | ||
| CVE-2017-15961 | Cri | 0.67 | 9.8 | 0.02 | Oct 29, 2017 | iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php. | ||
| CVE-2017-15960 | Cri | 0.67 | 9.8 | 0.02 | Oct 29, 2017 | Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php. | ||
| CVE-2017-15959 | Cri | 0.67 | 9.8 | 0.02 | Oct 29, 2017 | Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576. | ||
| CVE-2017-15958 | Cri | 0.67 | 9.8 | 0.02 | Oct 29, 2017 | D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php. | ||
| CVE-2014-2023 | Cri | 0.67 | 9.8 | 0.04 | Oct 26, 2017 | Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in… | ||
| CVE-2017-15081 | Cri | 0.67 | 9.8 | 0.02 | Oct 24, 2017 | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. | ||
| CVE-2017-15579 | Cri | 0.67 | 9.8 | 0.01 | Oct 18, 2017 | In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. | ||
| CVE-2015-2147 | Cri | 0.67 | 9.8 | 0.02 | Oct 6, 2017 | Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. | ||
| CVE-2017-6089 | Cri | 0.67 | 9.8 | 0.03 | Oct 3, 2017 | SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to… | ||
| CVE-2017-14738 | Cri | 0.67 | 9.8 | 0.03 | Sep 30, 2017 | FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function). | ||
| CVE-2017-14507 | Cri | 0.67 | 9.8 | 0.05 | Sep 29, 2017 | Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3)… | ||
| CVE-2017-14703 | Cri | 0.67 | 9.8 | 0.02 | Sep 26, 2017 | SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/. | ||
| CVE-2017-12930 | Cri | 0.67 | 9.8 | 0.03 | Sep 21, 2017 | SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password. | ||
| CVE-2015-4073 | Cri | 0.67 | 9.8 | 0.04 | Sep 20, 2017 | Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the… | ||
| CVE-2015-3313 | Cri | 0.67 | 9.8 | 0.08 | Sep 7, 2017 | SQL injection vulnerability in WordPress Community Events plugin before 1.4. |
- risk 0.67cvss 9.8epss 0.02
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.
- risk 0.67cvss 9.8epss 0.03
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.
- risk 0.67cvss 9.8epss 0.03
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.
- risk 0.67cvss 9.8epss 0.02
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
- risk 0.67cvss 9.8epss 0.02
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.
- risk 0.67cvss 9.8epss 0.02
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
- risk 0.67cvss 9.8epss 0.02
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
- risk 0.67cvss 9.8epss 0.02
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.
- risk 0.67cvss 9.8epss 0.02
D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.
- risk 0.67cvss 9.8epss 0.04
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in…
- risk 0.67cvss 9.8epss 0.02
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
- risk 0.67cvss 9.8epss 0.01
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
- risk 0.67cvss 9.8epss 0.02
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.
- risk 0.67cvss 9.8epss 0.03
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to…
- risk 0.67cvss 9.8epss 0.03
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
- risk 0.67cvss 9.8epss 0.05
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3)…
- risk 0.67cvss 9.8epss 0.02
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.
- risk 0.67cvss 9.8epss 0.03
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.
- risk 0.67cvss 9.8epss 0.04
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the…
- risk 0.67cvss 9.8epss 0.08
SQL injection vulnerability in WordPress Community Events plugin before 1.4.