CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 535 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41443 | Hig | 0.47 | 7.2 | 0.01 | Sep 18, 2023 | SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list. | ||
| CVE-2023-21521 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2023 | An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on… | ||
| CVE-2023-2188 | Hig | 0.47 | 7.2 | 0.01 | Aug 31, 2023 | The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | ||
| CVE-2023-31945 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php. | ||
| CVE-2023-31944 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php. | ||
| CVE-2023-31943 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php. | ||
| CVE-2023-31940 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php. | ||
| CVE-2023-31939 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php. | ||
| CVE-2023-31938 | Hig | 0.47 | 7.2 | 0.01 | Aug 17, 2023 | SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php. | ||
| CVE-2023-3864 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2023 | Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | ||
| CVE-2023-37687 | Hig | 0.47 | 7.2 | 0.01 | Aug 8, 2023 | Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal. | ||
| CVE-2023-4184 | Hig | 0.47 | 7.3 | 0.01 | Aug 6, 2023 | A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The… | ||
| CVE-2023-4182 | Hig | 0.47 | 7.3 | 0.01 | Aug 6, 2023 | A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely.… | ||
| CVE-2023-39121 | Hig | 0.47 | 7.2 | 0.03 | Aug 3, 2023 | emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php. | ||
| CVE-2023-21412 | Hig | 0.47 | 7.2 | 0.01 | Aug 3, 2023 | User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections. | ||
| CVE-2023-31937 | Hig | 0.47 | 7.2 | 0.01 | Jul 28, 2023 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file. | ||
| CVE-2023-31936 | Hig | 0.47 | 7.2 | 0.01 | Jul 28, 2023 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file. | ||
| CVE-2023-31933 | Hig | 0.47 | 7.2 | 0.01 | Jul 28, 2023 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file. | ||
| CVE-2023-31932 | Hig | 0.47 | 7.2 | 0.01 | Jul 28, 2023 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file. | ||
| CVE-2023-36968 | Hig | 0.47 | 7.2 | 0.01 | Jul 6, 2023 | A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter. |
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.
- risk 0.47cvss 7.2epss 0.01
An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on…
- risk 0.47cvss 7.2epss 0.01
The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the ticket_id parameter at ticket_detail.php.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php.
- risk 0.47cvss 7.2epss 0.01
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
- risk 0.47cvss 7.2epss 0.01
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The…
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely.…
- risk 0.47cvss 7.2epss 0.03
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
- risk 0.47cvss 7.2epss 0.01
User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injections.
- risk 0.47cvss 7.2epss 0.01
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file.
- risk 0.47cvss 7.2epss 0.01
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file.
- risk 0.47cvss 7.2epss 0.01
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file.
- risk 0.47cvss 7.2epss 0.01
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file.
- risk 0.47cvss 7.2epss 0.01
A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.