CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 538 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46946 | Hig | 0.47 | 7.2 | 0.01 | Jan 13, 2023 | Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_brand. | ||
| CVE-2022-46472 | Hig | 0.47 | 7.2 | 0.01 | Jan 12, 2023 | Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/classes/Users.php?f=delete. | ||
| CVE-2023-0254 | Hig | 0.47 | 7.2 | 0.01 | Jan 12, 2023 | The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with… | ||
| CVE-2022-4360 | Hig | 0.47 | 7.2 | 0.01 | Jan 2, 2023 | The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | ||
| CVE-2022-44137 | Hig | 0.47 | 7.2 | 0.01 | Dec 30, 2022 | SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-4739 | Hig | 0.47 | 7.3 | 0.01 | Dec 25, 2022 | A vulnerability classified as critical was found in SourceCodester School Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Admin Login. The manipulation leads to sql injection. The attack can be launched remotely. The… | ||
| CVE-2022-4737 | Hig | 0.47 | 7.3 | 0.01 | Dec 25, 2022 | A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated… | ||
| CVE-2022-45889 | Hig | 0.47 | 7.2 | 0.01 | Dec 25, 2022 | Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter). | ||
| CVE-2022-46127 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product. | ||
| CVE-2022-46126 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/brands/manage_brand.php?id=. | ||
| CVE-2022-46125 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=client/manage_client&id=. | ||
| CVE-2022-46124 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=user/manage_user&id=. | ||
| CVE-2022-46123 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=. | ||
| CVE-2022-46122 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=. | ||
| CVE-2022-46121 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/manage_product&id=. | ||
| CVE-2022-46120 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=. | ||
| CVE-2022-46119 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=. | ||
| CVE-2022-46118 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=. | ||
| CVE-2022-46117 | Hig | 0.47 | 7.2 | 0.01 | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=. | ||
| CVE-2022-46051 | Hig | 0.47 | 7.2 | 0.01 | Dec 13, 2022 | The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks. |
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_brand.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/classes/Users.php?f=delete.
- risk 0.47cvss 7.2epss 0.01
The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter. This makes it possible for authenticated attackers with…
- risk 0.47cvss 7.2epss 0.01
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
- risk 0.47cvss 7.2epss 0.01
SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection.
- risk 0.47cvss 7.3epss 0.01
A vulnerability classified as critical was found in SourceCodester School Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Admin Login. The manipulation leads to sql injection. The attack can be launched remotely. The…
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated…
- risk 0.47cvss 7.2epss 0.01
Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/brands/manage_brand.php?id=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=client/manage_client&id=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/manage_product&id=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=.
- risk 0.47cvss 7.2epss 0.01
Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=.
- risk 0.47cvss 7.2epss 0.01
The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.