CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 30 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30011 | Cri | 0.65 | 9.8 | 0.19 | May 16, 2022 | In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability. | ||
| CVE-2022-29009 | Cri | 0.65 | 9.8 | 0.23 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-29007 | Cri | 0.65 | 9.8 | 0.19 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-29006 | Cri | 0.65 | 9.8 | 0.19 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-0817 | Cri | 0.65 | 9.8 | 0.12 | May 9, 2022 | The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users | ||
| CVE-2020-19213 | Cri | 0.65 | 9.8 | 0.16 | May 6, 2022 | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. | ||
| CVE-2022-28080 | Hig | 0.65 | 8.8 | 0.57 | May 5, 2022 | Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter. | ||
| CVE-2022-1378 | Cri | 0.65 | 9.8 | 0.19 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1367 | Cri | 0.65 | 9.8 | 0.19 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-1366 | Cri | 0.65 | 9.8 | 0.19 | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands. | ||
| CVE-2022-28452 | Cri | 0.65 | 9.8 | 0.17 | Apr 29, 2022 | Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-29904 | Cri | 0.65 | 9.8 | 0.17 | Apr 29, 2022 | The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints. | ||
| CVE-2022-27927 | Cri | 0.65 | 9.8 | 0.14 | Apr 19, 2022 | A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter. | ||
| CVE-2022-0784 | Cri | 0.65 | 9.8 | 0.10 | Mar 28, 2022 | The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection | ||
| CVE-2022-26245 | Cri | 0.65 | 9.8 | 0.15 | Mar 27, 2022 | Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go. | ||
| CVE-2021-27472 | Cri | 0.65 | 10.0 | 0.06 | Mar 23, 2022 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements. | ||
| CVE-2021-27468 | Cri | 0.65 | 10.0 | 0.03 | Mar 23, 2022 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | ||
| CVE-2021-27464 | Cri | 0.65 | 10.0 | 0.03 | Mar 23, 2022 | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | ||
| CVE-2022-0747 | Cri | 0.65 | 9.8 | 0.15 | Mar 21, 2022 | The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection | ||
| CVE-2022-0434 | Cri | 0.65 | 9.8 | 0.15 | Mar 7, 2022 | The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL… |
- risk 0.65cvss 9.8epss 0.19
In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
- risk 0.65cvss 9.8epss 0.23
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.19
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.19
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.12
The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
- risk 0.65cvss 9.8epss 0.16
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
- risk 0.65cvss 8.8epss 0.57
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
- risk 0.65cvss 9.8epss 0.19
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.65cvss 9.8epss 0.19
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.65cvss 9.8epss 0.19
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.
- risk 0.65cvss 9.8epss 0.17
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
- risk 0.65cvss 9.8epss 0.17
The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.
- risk 0.65cvss 9.8epss 0.14
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
- risk 0.65cvss 9.8epss 0.10
The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection
- risk 0.65cvss 9.8epss 0.15
Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.
- risk 0.65cvss 10.0epss 0.06
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
- risk 0.65cvss 10.0epss 0.03
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
- risk 0.65cvss 10.0epss 0.03
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
- risk 0.65cvss 9.8epss 0.15
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
- risk 0.65cvss 9.8epss 0.15
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL…