CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 396 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31487 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection. | ||
| CVE-2022-30012 | Hig | 0.49 | 7.5 | 0.02 | May 16, 2022 | In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection. | ||
| CVE-2021-43010 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2022 | In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensitive data. | ||
| CVE-2021-41942 | Hig | 0.49 | 7.5 | 0.01 | Apr 29, 2022 | The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database. | ||
| CVE-2022-28060 | Hig | 0.49 | 7.5 | 0.02 | Apr 28, 2022 | SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. | ||
| CVE-2022-27386 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc. | ||
| CVE-2022-27385 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | ||
| CVE-2022-27384 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | ||
| CVE-2022-27381 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | ||
| CVE-2022-27380 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | ||
| CVE-2022-27379 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | ||
| CVE-2022-27378 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2022 | An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | ||
| CVE-2022-27041 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases. | ||
| CVE-2021-32957 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2022 | A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the… | ||
| CVE-2021-43109 | Hig | 0.49 | 7.5 | 0.01 | Mar 29, 2022 | An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php. | ||
| CVE-2021-44581 | Hig | 0.49 | 7.5 | 0.01 | Mar 29, 2022 | An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. | ||
| CVE-2021-44345 | Hig | 0.49 | 7.5 | 0.01 | Mar 20, 2022 | Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection. | ||
| CVE-2021-45794 | Hig | 0.49 | 7.5 | 0.01 | Mar 17, 2022 | Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained. | ||
| CVE-2021-45793 | Hig | 0.49 | 7.5 | 0.05 | Mar 17, 2022 | Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. | ||
| CVE-2022-25491 | Hig | 0.49 | 7.5 | 0.01 | Mar 15, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php. |
- risk 0.49cvss 7.5epss 0.01
Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
- risk 0.49cvss 7.5epss 0.02
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
- risk 0.49cvss 7.5epss 0.01
In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensitive data.
- risk 0.49cvss 7.5epss 0.01
The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.
- risk 0.49cvss 7.5epss 0.02
SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
- risk 0.49cvss 7.5epss 0.02
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
- risk 0.49cvss 7.5epss 0.02
An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
- risk 0.49cvss 7.5epss 0.02
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
- risk 0.49cvss 7.5epss 0.02
An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
- risk 0.49cvss 7.5epss 0.02
An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
- risk 0.49cvss 7.5epss 0.02
An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
- risk 0.49cvss 7.5epss 0.02
An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
- risk 0.49cvss 7.5epss 0.01
Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.
- risk 0.49cvss 7.5epss 0.01
A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the…
- risk 0.49cvss 7.5epss 0.01
An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
- risk 0.49cvss 7.5epss 0.01
An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
- risk 0.49cvss 7.5epss 0.01
Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.
- risk 0.49cvss 7.5epss 0.01
Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.
- risk 0.49cvss 7.5epss 0.05
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
- risk 0.49cvss 7.5epss 0.01
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.