CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 263 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28111 | Cri | 0.57 | 9.8 | 0.02 | May 4, 2022 | MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter. | ||
| CVE-2021-24957 | Hig | 0.57 | 8.8 | 0.01 | Apr 25, 2022 | The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection | ||
| CVE-2022-28020 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php. | ||
| CVE-2022-28019 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php. | ||
| CVE-2022-28018 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php. | ||
| CVE-2022-28017 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php. | ||
| CVE-2022-28016 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php. | ||
| CVE-2022-28015 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php. | ||
| CVE-2022-28014 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php. | ||
| CVE-2022-28013 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_employee_edit.php. | ||
| CVE-2022-28012 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_delete.php. | ||
| CVE-2022-28011 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php. | ||
| CVE-2022-28010 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php. | ||
| CVE-2022-28009 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. | ||
| CVE-2022-28008 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php. | ||
| CVE-2022-28007 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php. | ||
| CVE-2022-28006 | Hig | 0.57 | 8.8 | 0.01 | Apr 21, 2022 | Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php. | ||
| CVE-2022-28347 | Cri | 0.57 | 9.8 | 0.03 | Apr 12, 2022 | A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name. | ||
| CVE-2022-28000 | Hig | 0.57 | 8.8 | 0.02 | Apr 8, 2022 | Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter. | ||
| CVE-2022-27992 | Hig | 0.57 | 8.8 | 0.02 | Apr 8, 2022 | Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter. |
- risk 0.57cvss 9.8epss 0.02
MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.
- risk 0.57cvss 8.8epss 0.01
The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_employee_edit.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php.
- risk 0.57cvss 8.8epss 0.01
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.
- risk 0.57cvss 9.8epss 0.03
A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.
- risk 0.57cvss 8.8epss 0.02
Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.
- risk 0.57cvss 8.8epss 0.02
Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.