CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 393 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-31607 | Hig | 0.49 | 7.5 | 0.01 | May 15, 2023 | An issue in the __libc_malloc component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | ||
| CVE-2023-30243 | Hig | 0.49 | 7.5 | 0.01 | May 5, 2023 | Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information. | ||
| CVE-2023-30112 | Hig | 0.49 | 7.5 | 0.01 | Apr 26, 2023 | Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection. | ||
| CVE-2023-27649 | Hig | 0.49 | 7.5 | 0.01 | Apr 14, 2023 | SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table | ||
| CVE-2023-29626 | Hig | 0.49 | 7.5 | 0.01 | Apr 14, 2023 | Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php. | ||
| CVE-2022-46021 | Hig | 0.49 | 7.5 | 0.01 | Mar 31, 2023 | X-Man 1.0 has a SQL injection vulnerability, which can cause data leakage. | ||
| CVE-2023-27871 | Hig | 0.49 | 7.5 | 0.01 | Mar 21, 2023 | IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. | ||
| CVE-2021-34249 | Hig | 0.49 | 7.5 | 0.01 | Feb 24, 2023 | SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL. | ||
| CVE-2021-32441 | Hig | 0.49 | 7.5 | 0.01 | Feb 17, 2023 | SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class. | ||
| CVE-2021-38239 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10. | ||
| CVE-2021-34117 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information. | ||
| CVE-2023-24647 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2023 | Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter. | ||
| CVE-2021-37316 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow. | ||
| CVE-2021-36432 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php. | ||
| CVE-2023-0324 | Hig | 0.49 | 7.3 | 0.19 | Jan 16, 2023 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack… | ||
| CVE-2022-40049 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2023 | SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page. | ||
| CVE-2022-45041 | Hig | 0.49 | 7.5 | 0.01 | Dec 19, 2022 | SQL Injection exits in xinhu < 2.5.0 | ||
| CVE-2022-44790 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2022 | Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists. | ||
| CVE-2022-45019 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter. | ||
| CVE-2022-45329 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information. |
- risk 0.49cvss 7.5epss 0.01
An issue in the __libc_malloc component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- risk 0.49cvss 7.5epss 0.01
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
- risk 0.49cvss 7.5epss 0.01
Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.
- risk 0.49cvss 7.5epss 0.01
SQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to cause a denial of service via the search history table
- risk 0.49cvss 7.5epss 0.01
Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php.
- risk 0.49cvss 7.5epss 0.01
X-Man 1.0 has a SQL injection vulnerability, which can cause data leakage.
- risk 0.49cvss 7.5epss 0.01
IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613.
- risk 0.49cvss 7.5epss 0.01
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
- risk 0.49cvss 7.5epss 0.01
SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.
- risk 0.49cvss 7.5epss 0.01
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10.
- risk 0.49cvss 7.5epss 0.01
SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.
- risk 0.49cvss 7.5epss 0.01
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
- risk 0.49cvss 7.5epss 0.01
SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to view sensitive information via /etc/shadow.
- risk 0.49cvss 7.5epss 0.01
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php.
- risk 0.49cvss 7.3epss 0.19
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack…
- risk 0.49cvss 7.5epss 0.01
SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page.
- risk 0.49cvss 7.5epss 0.01
SQL Injection exits in xinhu < 2.5.0
- risk 0.49cvss 7.5epss 0.01
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
- risk 0.49cvss 7.5epss 0.01
SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.
- risk 0.49cvss 7.5epss 0.01
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.