CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,858)
page 346 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-47062 | Hig | 0.51 | 8.8 | 0.04 | Sep 20, 2024 | Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding parameters like `password=...` in the URL (ORM Leak). Furthermore, the names of… | ||
| CVE-2024-42679 | Hig | 0.51 | 7.8 | 0.00 | Aug 15, 2024 | SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component. | ||
| CVE-2024-6497 | Hig | 0.51 | 8.8 | 0.11 | Jul 20, 2024 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | ||
| CVE-2024-25513 | Hig | 0.51 | 7.8 | 0.00 | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx. | ||
| CVE-2024-28521 | Hig | 0.51 | 7.8 | 0.00 | Mar 21, 2024 | SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component. | ||
| CVE-2024-24105 | Hig | 0.51 | 7.8 | 0.00 | Mar 13, 2024 | SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php. | ||
| CVE-2024-24092 | Hig | 0.51 | 7.8 | 0.00 | Mar 12, 2024 | SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php. | ||
| CVE-2024-24098 | Hig | 0.51 | 7.8 | 0.00 | Mar 5, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed. | ||
| CVE-2024-27718 | Hig | 0.51 | 7.8 | 0.01 | Mar 5, 2024 | SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component. | ||
| CVE-2024-24096 | Hig | 0.51 | 7.8 | 0.00 | Feb 27, 2024 | Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN. | ||
| CVE-2023-48645 | Hig | 0.51 | 7.8 | 0.00 | Feb 2, 2024 | An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in… | ||
| CVE-2023-46989 | Hig | 0.51 | 7.8 | 0.00 | Dec 28, 2023 | SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file. | ||
| CVE-2023-46582 | Hig | 0.51 | 7.8 | 0.00 | Nov 14, 2023 | SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component. | ||
| CVE-2023-38899 | Hig | 0.51 | 7.8 | 0.00 | Aug 21, 2023 | SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component. | ||
| CVE-2023-0562 | Hig | 0.51 | 7.3 | 0.44 | Jan 28, 2023 | A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The… | ||
| CVE-2022-46623 | Hig | 0.51 | 7.8 | 0.00 | Jan 12, 2023 | Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2022-39323 | Hig | 0.51 | 7.4 | 0.34 | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been… | ||
| CVE-2022-3323 | Hig | 0.51 | 7.5 | 0.29 | Sep 27, 2022 | An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration… | ||
| CVE-2022-29058 | Hig | 0.51 | 7.8 | 0.00 | Sep 6, 2022 | An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP 6.0.0 through 6.4.7, 7.0.0 through 7.0.3, 7.2.0, FortiAP-S 6.0.0 through 6.4.7, FortiAP-W2 6.0.0 through 6.4.7, 7.0.0 through 7.0.3,… | ||
| CVE-2022-31101 | Hig | 0.51 | 8.1 | 0.23 | Jun 27, 2022 | prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds… |
- risk 0.51cvss 8.8epss 0.04
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited to access information by adding parameters like `password=...` in the URL (ORM Leak). Furthermore, the names of…
- risk 0.51cvss 7.8epss 0.00
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
- risk 0.51cvss 8.8epss 0.11
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
- risk 0.51cvss 7.8epss 0.00
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /CorporateCulture/kaizen_download.aspx.
- risk 0.51cvss 7.8epss 0.00
SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.
- risk 0.51cvss 7.8epss 0.00
SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.
- risk 0.51cvss 7.8epss 0.00
SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.
- risk 0.51cvss 7.8epss 0.00
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.
- risk 0.51cvss 7.8epss 0.01
SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.
- risk 0.51cvss 7.8epss 0.00
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in…
- risk 0.51cvss 7.8epss 0.00
SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.
- risk 0.51cvss 7.8epss 0.00
SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component.
- risk 0.51cvss 7.8epss 0.00
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.
- risk 0.51cvss 7.3epss 0.44
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The…
- risk 0.51cvss 7.8epss 0.00
Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.51cvss 7.4epss 0.34
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and software auditing. Time based attack using a SQL injection in api REST user_token. This issue has been…
- risk 0.51cvss 7.5epss 0.29
An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration…
- risk 0.51cvss 7.8epss 0.00
An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP 6.0.0 through 6.4.7, 7.0.0 through 7.0.3, 7.2.0, FortiAP-S 6.0.0 through 6.4.7, FortiAP-W2 6.0.0 through 6.4.7, 7.0.0 through 7.0.3,…
- risk 0.51cvss 8.1epss 0.23
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds…