CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 541 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43068 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation. | ||
| CVE-2022-43066 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message. | ||
| CVE-2022-43227 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment. | ||
| CVE-2022-41551 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php. | ||
| CVE-2022-43362 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php. | ||
| CVE-2022-43331 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php. | ||
| CVE-2022-43330 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php. | ||
| CVE-2022-43329 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php. | ||
| CVE-2022-43328 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php. | ||
| CVE-2022-43127 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php. | ||
| CVE-2022-43126 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/manage_test.php. | ||
| CVE-2022-43125 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php. | ||
| CVE-2022-43124 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user. | ||
| CVE-2022-43355 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service. | ||
| CVE-2022-43354 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/manage_request. | ||
| CVE-2022-43353 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order. | ||
| CVE-2022-43233 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php. | ||
| CVE-2022-43232 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php. | ||
| CVE-2022-43230 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details. | ||
| CVE-2022-43229 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php. |
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Master.php?f=delete_message.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/admin/?page=appointments/view_appointment.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.
- risk 0.47cvss 7.2epss 0.01
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/manage_test.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/manage_request.
- risk 0.47cvss 7.2epss 0.01
Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php.
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.