CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 550 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32343 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via hprms/admin/room_types/manage_room_type.php?id=. | ||
| CVE-2022-32342 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/room_types/view_room_type.php?id=. | ||
| CVE-2022-32341 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-32340 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=patients/view_patient&id=. | ||
| CVE-2022-32339 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/view_doctor.php?id=. | ||
| CVE-2022-32338 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/manage_doctor.php?id=. | ||
| CVE-2022-32335 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=. | ||
| CVE-2022-32334 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=. | ||
| CVE-2022-32333 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=. | ||
| CVE-2022-32332 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category. | ||
| CVE-2022-32331 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=. | ||
| CVE-2022-32330 | Hig | 0.47 | 7.2 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu. | ||
| CVE-2022-1800 | Hig | 0.47 | 7.2 | 0.01 | Jun 13, 2022 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability. | ||
| CVE-2022-32028 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=. | ||
| CVE-2022-32027 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=manage_car&id=. | ||
| CVE-2022-32026 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=. | ||
| CVE-2022-32025 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=. | ||
| CVE-2022-32024 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=. | ||
| CVE-2022-32022 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login. | ||
| CVE-2022-32021 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement.php?id=. |
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via hprms/admin/room_types/manage_room_type.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/room_types/view_room_type.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/?page=patients/view_patient&id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/view_doctor.php?id=.
- risk 0.47cvss 7.2epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/doctors/manage_doctor.php?id=.
- risk 0.47cvss 7.2epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=.
- risk 0.47cvss 7.2epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=.
- risk 0.47cvss 7.2epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=.
- risk 0.47cvss 7.2epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category.
- risk 0.47cvss 7.2epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=.
- risk 0.47cvss 7.2epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu.
- risk 0.47cvss 7.2epss 0.01
The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.
- risk 0.47cvss 7.2epss 0.05
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.
- risk 0.47cvss 7.2epss 0.01
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=manage_car&id=.
- risk 0.47cvss 7.2epss 0.05
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.
- risk 0.47cvss 7.2epss 0.05
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.
- risk 0.47cvss 7.2epss 0.05
Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
- risk 0.47cvss 7.2epss 0.05
Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.
- risk 0.47cvss 7.2epss 0.01
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement.php?id=.