CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 404 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13191 | Hig | 0.49 | 7.5 | 0.01 | Sep 5, 2019 | A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page. | ||
| CVE-2019-14937 | Hig | 0.49 | 7.5 | 0.01 | Aug 17, 2019 | REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to… | ||
| CVE-2017-18406 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2019 | cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276). | ||
| CVE-2019-12946 | Hig | 0.49 | 7.5 | 0.01 | Jul 19, 2019 | Elcom CMS before 10.7 has SQL Injection via EventSearchByState.aspx and EventSearchAdv.aspx. | ||
| CVE-2017-11559 | Hig | 0.49 | 7.5 | 0.04 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack. | ||
| CVE-2019-11880 | Hig | 0.49 | 7.5 | 0.02 | May 22, 2019 | CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2. | ||
| CVE-2018-17048 | Hig | 0.49 | 7.5 | 0.02 | May 16, 2019 | admin/Lib/Action/FpluginAction.class.php in FDCMS (aka Fangfa Content Manage System) 4.2 allows SQL Injection. | ||
| CVE-2017-12761 | Hig | 0.49 | 7.5 | 0.03 | May 9, 2019 | http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explore… | ||
| CVE-2019-11614 | Hig | 0.49 | 7.5 | 0.02 | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information. | ||
| CVE-2018-20505 | Hig | 0.49 | 7.5 | 0.07 | Apr 3, 2019 | SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). | ||
| CVE-2018-20730 | Hig | 0.49 | 7.5 | 0.01 | Jan 17, 2019 | A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component. | ||
| CVE-2019-5488 | Hig | 0.49 | 7.5 | 0.01 | Jan 7, 2019 | EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database. | ||
| CVE-2019-3494 | Hig | 0.49 | 7.5 | 0.01 | Jan 1, 2019 | Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter. | ||
| CVE-2018-1000890 | Hig | 0.49 | 7.5 | 0.02 | Dec 28, 2018 | FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application. | ||
| CVE-2018-20061 | Hig | 0.49 | 7.5 | 0.01 | Dec 11, 2018 | A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a… | ||
| CVE-2018-20018 | Hig | 0.49 | 7.5 | 0.01 | Dec 10, 2018 | S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI. | ||
| CVE-2018-19331 | Hig | 0.49 | 7.5 | 0.01 | Nov 17, 2018 | An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter. | ||
| CVE-2018-0404 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2018 | A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker could retrieve… | ||
| CVE-2018-17562 | Hig | 0.49 | 7.5 | 0.01 | Oct 3, 2018 | Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points. | ||
| CVE-2018-16384 | Hig | 0.49 | 7.5 | 0.02 | Sep 3, 2018 | A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed. |
- risk 0.49cvss 7.5epss 0.01
A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page.
- risk 0.49cvss 7.5epss 0.01
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to…
- risk 0.49cvss 7.5epss 0.01
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
- risk 0.49cvss 7.5epss 0.01
Elcom CMS before 10.7 has SQL Injection via EventSearchByState.aspx and EventSearchAdv.aspx.
- risk 0.49cvss 7.5epss 0.04
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
- risk 0.49cvss 7.5epss 0.02
CommSy through 8.6.5 has SQL Injection via the cid parameter. This is fixed in 9.2.
- risk 0.49cvss 7.5epss 0.02
admin/Lib/Action/FpluginAction.class.php in FDCMS (aka Fangfa Content Manage System) 4.2 allows SQL Injection.
- risk 0.49cvss 7.5epss 0.03
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explore…
- risk 0.49cvss 7.5epss 0.02
doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attacker could exploit the vulnerability to obtain database sensitive information.
- risk 0.49cvss 7.5epss 0.07
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
- risk 0.49cvss 7.5epss 0.01
A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.
- risk 0.49cvss 7.5epss 0.01
EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database.
- risk 0.49cvss 7.5epss 0.01
Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.
- risk 0.49cvss 7.5epss 0.02
FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.
- risk 0.49cvss 7.5epss 0.01
A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a…
- risk 0.49cvss 7.5epss 0.01
S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.
- risk 0.49cvss 7.5epss 0.01
A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker could retrieve…
- risk 0.49cvss 7.5epss 0.01
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.
- risk 0.49cvss 7.5epss 0.02
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.