CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,858)
page 341 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20613 | Hig | 0.53 | 8.1 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is SVE-2018-13452 (March 2019). | ||
| CVE-2020-8435 | Hig | 0.53 | 8.1 | 0.02 | Mar 12, 2020 | An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter. | ||
| CVE-2020-9265 | Hig | 0.53 | 8.2 | 0.01 | Feb 18, 2020 | phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username. | ||
| CVE-2020-3937 | Hig | 0.53 | 8.1 | 0.01 | Feb 4, 2020 | SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries and access arbitrary file in the database. | ||
| CVE-2014-3868 | Hig | 0.53 | 8.8 | 0.02 | Jan 31, 2020 | Multiple SQL injection vulnerabilities in ZeusCart 4.x. | ||
| CVE-2014-3119 | — | Hig | 0.53 | 8.8 | 0.02 | Jan 31, 2020 | Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search_string parameter in the contacts module to index.php or allow remote attackers to execute arbitrary SQL commands via the… | |
| CVE-2017-14807 | Hig | 0.53 | 8.1 | 0.01 | Jan 27, 2020 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data.… | ||
| CVE-2014-5140 | Hig | 0.53 | 8.8 | 0.03 | Jan 3, 2020 | The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book. | ||
| CVE-2019-3661 | Hig | 0.53 | 8.1 | 0.01 | Nov 14, 2019 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads. | ||
| CVE-2017-18614 | Hig | 0.53 | 8.1 | 0.02 | Sep 13, 2019 | The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter. | ||
| CVE-2019-12465 | Hig | 0.53 | 8.1 | 0.01 | Sep 9, 2019 | An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request. | ||
| CVE-2016-10839 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71). | ||
| CVE-2019-12374 | Hig | 0.53 | 8.1 | 0.03 | Jun 3, 2019 | A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in… | ||
| CVE-2017-11738 | Hig | 0.53 | 8.1 | 0.04 | May 23, 2019 | In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack. | ||
| CVE-2019-1825 | Hig | 0.53 | 8.1 | 0.02 | May 16, 2019 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly… | ||
| CVE-2019-1824 | Hig | 0.53 | 8.1 | 0.02 | May 16, 2019 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly… | ||
| CVE-2018-20329 | Hig | 0.53 | 8.1 | 0.01 | Dec 21, 2018 | Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information. | ||
| CVE-2018-18211 | Hig | 0.53 | 8.1 | 0.01 | Oct 10, 2018 | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. | ||
| CVE-2018-1756 | Hig | 0.53 | 7.5 | 0.11 | Sep 7, 2018 | IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599. | ||
| CVE-2018-11231 | Hig | 0.53 | 8.1 | 0.09 | May 23, 2018 | In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information. |
- risk 0.53cvss 8.1epss 0.00
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is SVE-2018-13452 (March 2019).
- risk 0.53cvss 8.1epss 0.02
An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter.
- risk 0.53cvss 8.2epss 0.01
phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username.
- risk 0.53cvss 8.1epss 0.01
SQL Injection in SysJust Syuan-Gu-Da-Shih, versions before 20191223, allowing attackers to perform unwanted SQL queries and access arbitrary file in the database.
- risk 0.53cvss 8.8epss 0.02
Multiple SQL injection vulnerabilities in ZeusCart 4.x.
- risk 0.53cvss 8.8epss 0.02
Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search_string parameter in the contacts module to index.php or allow remote attackers to execute arbitrary SQL commands via the…
- risk 0.53cvss 8.1epss 0.01
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data.…
- risk 0.53cvss 8.8epss 0.03
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.
- risk 0.53cvss 8.1epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.
- risk 0.53cvss 8.1epss 0.02
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request.
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).
- risk 0.53cvss 8.1epss 0.03
A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in…
- risk 0.53cvss 8.1epss 0.04
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
- risk 0.53cvss 8.1epss 0.02
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly…
- risk 0.53cvss 8.1epss 0.02
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary SQL queries. This vulnerability exist because the software improperly…
- risk 0.53cvss 8.1epss 0.01
Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.
- risk 0.53cvss 8.1epss 0.01
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
- risk 0.53cvss 7.5epss 0.11
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599.
- risk 0.53cvss 8.1epss 0.09
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.