CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 539 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44838 | Hig | 0.47 | 7.2 | 0.01 | Dec 9, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php. | ||
| CVE-2022-44393 | Hig | 0.47 | 7.2 | 0.01 | Dec 7, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=. | ||
| CVE-2022-44348 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=. | ||
| CVE-2022-44347 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=. | ||
| CVE-2022-44345 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=. | ||
| CVE-2022-44277 | Hig | 0.47 | 7.2 | 0.01 | Dec 2, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product. | ||
| CVE-2022-44296 | Hig | 0.47 | 7.2 | 0.01 | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=. | ||
| CVE-2022-44295 | Hig | 0.47 | 7.2 | 0.01 | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=. | ||
| CVE-2022-44294 | Hig | 0.47 | 7.2 | 0.01 | Nov 30, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=. | ||
| CVE-2022-45328 | Hig | 0.47 | 7.2 | 0.01 | Nov 30, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php. | ||
| CVE-2022-3689 | Hig | 0.47 | 7.2 | 0.02 | Nov 28, 2022 | The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users | ||
| CVE-2022-44860 | Hig | 0.47 | 7.2 | 0.01 | Nov 25, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/transactions/update_status.php. | ||
| CVE-2022-44859 | Hig | 0.47 | 7.2 | 0.01 | Nov 25, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/admin/products/manage_product.php. | ||
| CVE-2022-44858 | Hig | 0.47 | 7.2 | 0.01 | Nov 25, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php. | ||
| CVE-2022-4088 | Hig | 0.47 | 7.3 | 0.01 | Nov 24, 2022 | A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched… | ||
| CVE-2022-44278 | Hig | 0.47 | 7.2 | 0.01 | Nov 23, 2022 | Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-44820 | Hig | 0.47 | 7.2 | 0.01 | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=transactions/manage_transaction&id=. | ||
| CVE-2022-44415 | Hig | 0.47 | 7.2 | 0.01 | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/view_mechanic.php?id=. | ||
| CVE-2022-44414 | Hig | 0.47 | 7.2 | 0.01 | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/services/manage_service.php?id=. | ||
| CVE-2022-44413 | Hig | 0.47 | 7.2 | 0.01 | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/manage_mechanic.php?id=. |
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=.
- risk 0.47cvss 7.2epss 0.01
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.
- risk 0.47cvss 7.2epss 0.02
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/transactions/update_status.php.
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/admin/products/manage_product.php.
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched…
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=transactions/manage_transaction&id=.
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/view_mechanic.php?id=.
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/services/manage_service.php?id=.
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/manage_mechanic.php?id=.