CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 272 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20678 | Hig | 0.57 | 8.8 | 0.02 | Mar 18, 2021 | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | ||
| CVE-2020-24617 | Hig | 0.57 | 8.8 | 0.01 | Feb 19, 2021 | Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped. | ||
| CVE-2020-22425 | Hig | 0.57 | 8.8 | 0.02 | Feb 15, 2021 | Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution. | ||
| CVE-2019-25019 | Cri | 0.57 | 9.8 | 0.01 | Feb 14, 2021 | LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. | ||
| CVE-2021-26751 | Hig | 0.57 | 8.8 | 0.01 | Feb 12, 2021 | NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application. | ||
| CVE-2020-18215 | Hig | 0.57 | 8.8 | 0.02 | Feb 9, 2021 | Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code. | ||
| CVE-2020-29163 | Hig | 0.57 | 8.8 | 0.01 | Feb 3, 2021 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection. | ||
| CVE-2021-22847 | Hig | 0.57 | 8.8 | 0.02 | Jan 22, 2021 | Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands without privilege. | ||
| CVE-2021-1248 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of… | ||
| CVE-2021-1247 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of… | ||
| CVE-2020-4921 | Hig | 0.57 | 8.8 | 0.01 | Jan 20, 2021 | IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398. | ||
| CVE-2021-22852 | Hig | 0.57 | 8.8 | 0.01 | Jan 19, 2021 | HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data. | ||
| CVE-2020-23630 | Hig | 0.57 | 8.8 | 0.01 | Jan 11, 2021 | A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection). | ||
| CVE-2021-3025 | Hig | 0.57 | 8.8 | 0.01 | Jan 8, 2021 | Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php). | ||
| CVE-2020-26773 | Hig | 0.57 | 8.8 | 0.02 | Jan 7, 2021 | Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php. | ||
| CVE-2019-7726 | Cri | 0.57 | 9.8 | 0.02 | Dec 31, 2020 | modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent). | ||
| CVE-2020-27848 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2020 | dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection… | ||
| CVE-2020-35666 | Hig | 0.57 | 8.8 | 0.01 | Dec 23, 2020 | Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value. | ||
| CVE-2020-28860 | Hig | 0.57 | 8.8 | 0.02 | Dec 14, 2020 | OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection. | ||
| CVE-2020-13526 | Hig | 0.57 | 8.8 | 0.02 | Dec 10, 2020 | SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make… |
- risk 0.57cvss 8.8epss 0.02
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.
- risk 0.57cvss 8.8epss 0.02
Centreon 19.10-3.el7 is affected by a SQL injection vulnerability, where an authorized user is able to inject additional SQL queries to perform remote command execution.
- risk 0.57cvss 9.8epss 0.01
LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.
- risk 0.57cvss 8.8epss 0.01
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint /Monitoring-History.php via the det HTTP GET parameter. This allows an attacker to access all the data in the database and obtain access to the NeDi application.
- risk 0.57cvss 8.8epss 0.02
Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, which could let a remote malicious user execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
- risk 0.57cvss 8.8epss 0.02
Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands without privilege.
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of…
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. For more information about these vulnerabilities, see the Details section of…
- risk 0.57cvss 8.8epss 0.01
IBM Security Guardium 10.6 and 11.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 191398.
- risk 0.57cvss 8.8epss 0.01
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (online registration) to obtain database schema and data.
- risk 0.57cvss 8.8epss 0.01
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
- risk 0.57cvss 8.8epss 0.01
Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php).
- risk 0.57cvss 8.8epss 0.02
Restaurant Reservation System 1.0 suffers from an authenticated SQL injection vulnerability, which allows a remote, authenticated attacker to execute arbitrary SQL commands via the date parameter in includes/reservation.inc.php.
- risk 0.57cvss 9.8epss 0.02
modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent).
- risk 0.57cvss 8.8epss 0.01
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection…
- risk 0.57cvss 8.8epss 0.01
Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.
- risk 0.57cvss 8.8epss 0.02
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
- risk 0.57cvss 8.8epss 0.02
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make…