CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 547 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-35421 | Hig | 0.47 | 7.2 | 0.01 | Aug 2, 2022 | Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname parameter at /admin/operations/packages.php. | ||
| CVE-2022-34590 | Hig | 0.47 | 7.2 | 0.05 | Jul 20, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php. | ||
| CVE-2022-34042 | Hig | 0.47 | 7.2 | 0.01 | Jul 20, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php. | ||
| CVE-2022-32416 | Hig | 0.47 | 7.2 | 0.01 | Jul 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product. | ||
| CVE-2021-44915 | Hig | 0.47 | 7.2 | 0.01 | Jul 5, 2022 | Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category. | ||
| CVE-2022-33061 | Hig | 0.47 | 7.2 | 0.01 | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service. | ||
| CVE-2022-33060 | Hig | 0.47 | 7.2 | 0.01 | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. | ||
| CVE-2022-33059 | Hig | 0.47 | 7.2 | 0.01 | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_train. | ||
| CVE-2022-33058 | Hig | 0.47 | 7.2 | 0.01 | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_message. | ||
| CVE-2022-33057 | Hig | 0.47 | 7.2 | 0.01 | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation. | ||
| CVE-2022-31058 | Hig | 0.47 | 7.2 | 0.01 | Jun 29, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the… | ||
| CVE-2022-33042 | Hig | 0.47 | 7.2 | 0.01 | Jun 29, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php. | ||
| CVE-2022-32400 | Hig | 0.47 | 7.2 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4. | ||
| CVE-2022-33114 | Hig | 0.47 | 7.2 | 0.01 | Jun 23, 2022 | Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list. | ||
| CVE-2021-40955 | Hig | 0.47 | 7.2 | 0.01 | Jun 23, 2022 | SQL injection exists in LaiKetui v3.5.0 the background administrator list. | ||
| CVE-2022-33056 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php. | ||
| CVE-2022-33055 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php. | ||
| CVE-2022-33049 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user. | ||
| CVE-2022-33048 | Hig | 0.47 | 7.2 | 0.01 | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php. | ||
| CVE-2022-1472 | Hig | 0.47 | 7.2 | 0.01 | Jun 20, 2022 | The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection |
- risk 0.47cvss 7.2epss 0.01
Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname parameter at /admin/operations/packages.php.
- risk 0.47cvss 7.2epss 0.05
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
- risk 0.47cvss 7.2epss 0.01
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.
- risk 0.47cvss 7.2epss 0.01
Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_train.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_message.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.
- risk 0.47cvss 7.2epss 0.01
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the…
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php.
- risk 0.47cvss 7.2epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.
- risk 0.47cvss 7.2epss 0.01
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
- risk 0.47cvss 7.2epss 0.01
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.
- risk 0.47cvss 7.2epss 0.01
Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.
- risk 0.47cvss 7.2epss 0.01
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection