CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 551 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32018 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=. | ||
| CVE-2022-32017 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bytitle. | ||
| CVE-2022-32016 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bycompany. | ||
| CVE-2022-32015 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=. | ||
| CVE-2022-32014 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction. | ||
| CVE-2022-32013 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=. | ||
| CVE-2022-32012 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/employee/index.php?view=edit&id=. | ||
| CVE-2022-32011 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/applicants/index.php?view=view&id=. | ||
| CVE-2022-32010 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/user/index.php?view=edit&id=. | ||
| CVE-2022-32008 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/vacancy/index.php?view=edit&id=. | ||
| CVE-2022-32007 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=. | ||
| CVE-2022-31994 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=sales/view_details&id. | ||
| CVE-2022-31992 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=court_rentals/view_court_rental&id=. | ||
| CVE-2022-31988 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=reports/daily_services_report&date=. | ||
| CVE-2022-31986 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_court_rental_report&date=. | ||
| CVE-2022-31985 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_sales_report&date=. | ||
| CVE-2022-32006 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/services/view_service.php?id=. | ||
| CVE-2022-32005 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/services/manage_service.php?id=. | ||
| CVE-2022-32004 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/manage_product.php?id=. | ||
| CVE-2022-32003 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/view_court.php?id=. |
- risk 0.47cvss 7.2epss 0.05
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bytitle.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bycompany.
- risk 0.47cvss 7.2epss 0.05
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/employee/index.php?view=edit&id=.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/applicants/index.php?view=view&id=.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/user/index.php?view=edit&id=.
- risk 0.47cvss 7.2epss 0.01
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/vacancy/index.php?view=edit&id=.
- risk 0.47cvss 7.2epss 0.05
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=sales/view_details&id.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=court_rentals/view_court_rental&id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=reports/daily_services_report&date=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_court_rental_report&date=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=reports/daily_sales_report&date=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/services/view_service.php?id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/services/manage_service.php?id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/manage_product.php?id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/view_court.php?id=.