CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 549 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32992 | Hig | 0.47 | 7.2 | 0.01 | Jun 15, 2022 | Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname parameter at /admin/operations/tax.php. | ||
| CVE-2022-32363 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/view_category.php?id=. | ||
| CVE-2022-32362 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_category.php?id=. | ||
| CVE-2022-32359 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_category. | ||
| CVE-2022-32358 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_inquiry. | ||
| CVE-2022-32355 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=products/view_product&id=. | ||
| CVE-2022-32354 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=user/manage_user&id=. | ||
| CVE-2022-32353 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_field_order.php?id=. | ||
| CVE-2022-32367 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=inquiries/view_inquiry&id=. | ||
| CVE-2022-32366 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/fields/view_field.php?id=. | ||
| CVE-2022-32365 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/fields/manage_field.php?id=. | ||
| CVE-2022-32364 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=products/manage_product&id=. | ||
| CVE-2022-32351 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_message. | ||
| CVE-2022-32350 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room_type. | ||
| CVE-2022-32349 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_history. | ||
| CVE-2022-32348 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_doctor. | ||
| CVE-2022-32347 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room. | ||
| CVE-2022-32346 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/view_room.php?id=. | ||
| CVE-2022-32345 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/manage_room.php?id=. | ||
| CVE-2022-32344 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient. |
- risk 0.47cvss 7.2epss 0.01
Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname parameter at /admin/operations/tax.php.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/view_category.php?id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_category.php?id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_category.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_inquiry.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=products/view_product&id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/manage_field_order.php?id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=inquiries/view_inquiry&id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/fields/view_field.php?id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/fields/manage_field.php?id=.
- risk 0.47cvss 7.2epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/?page=products/manage_product&id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_message.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room_type.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_history.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_doctor.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_room.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/view_room.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/rooms/manage_room.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient.