CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 548 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-12359 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2019-12357 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2019-12354 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2019-12353 | Hig | 0.47 | 7.2 | 0.01 | Jun 17, 2022 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter. | ||
| CVE-2022-31912 | Hig | 0.47 | 7.2 | 0.01 | Jun 16, 2022 | Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team. | ||
| CVE-2022-31911 | Hig | 0.47 | 7.2 | 0.01 | Jun 16, 2022 | Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team. | ||
| CVE-2022-31908 | Hig | 0.47 | 7.2 | 0.01 | Jun 16, 2022 | Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php. | ||
| CVE-2022-32372 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=. | ||
| CVE-2022-32371 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher.php?id=. | ||
| CVE-2022-32370 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_classroom.php?id=. | ||
| CVE-2022-32374 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject_routing.php?id=. | ||
| CVE-2022-32373 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam.php?id=. | ||
| CVE-2022-32368 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_grade.php?id=. | ||
| CVE-2022-32381 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_admin_profile.php?my_index=. | ||
| CVE-2022-32380 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_student_subject.php?index=. | ||
| CVE-2022-32379 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_parents_profile.php?my_index=. | ||
| CVE-2022-32378 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher_profile.php?my_index=. | ||
| CVE-2022-32377 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam_timetable.php?id=. | ||
| CVE-2022-32376 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=. | ||
| CVE-2022-32375 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=. |
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.
- risk 0.47cvss 7.2epss 0.01
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
- risk 0.47cvss 7.2epss 0.01
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
- risk 0.47cvss 7.2epss 0.01
Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher.php?id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_classroom.php?id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject_routing.php?id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam.php?id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_grade.php?id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_admin_profile.php?my_index=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_student_subject.php?index=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_parents_profile.php?my_index=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher_profile.php?my_index=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam_timetable.php?id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=.
- risk 0.47cvss 7.2epss 0.01
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=.