CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 552 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32001 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/view_product.php?id=. | ||
| CVE-2022-32000 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/manage_service_transaction&id=. | ||
| CVE-2022-31998 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/view_details&id=. | ||
| CVE-2022-31996 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=sales/manage_sale&id=. | ||
| CVE-2022-31984 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=. | ||
| CVE-2022-31983 | Hig | 0.47 | 7.2 | 0.03 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=. | ||
| CVE-2022-31982 | Hig | 0.47 | 7.2 | 0.02 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=. | ||
| CVE-2022-31981 | Hig | 0.47 | 7.2 | 0.02 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/view_team&id=. | ||
| CVE-2022-31980 | Hig | 0.47 | 7.2 | 0.02 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/manage_team&id=. | ||
| CVE-2022-31975 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=. | ||
| CVE-2022-31974 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=. | ||
| CVE-2022-31971 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/view_response&id=. | ||
| CVE-2022-31970 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/manage_response&id=. | ||
| CVE-2022-31339 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php. | ||
| CVE-2022-30836 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php. | ||
| CVE-2022-30835 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=. | ||
| CVE-2022-30834 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id= | ||
| CVE-2022-30833 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_edit.php?booking=31&user_id=. | ||
| CVE-2022-30832 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=. | ||
| CVE-2022-30831 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via Wedding-Management/wedding_details.php. |
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/products/view_product.php?id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/manage_service_transaction&id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=service_transactions/view_details&id=.
- risk 0.47cvss 7.2epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/admin/?page=sales/manage_sale&id=.
- risk 0.47cvss 7.2epss 0.05
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/requests/take_action.php?id=.
- risk 0.47cvss 7.2epss 0.03
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/manage_request&id=.
- risk 0.47cvss 7.2epss 0.02
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=requests/view_request&id=.
- risk 0.47cvss 7.2epss 0.02
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/view_team&id=.
- risk 0.47cvss 7.2epss 0.02
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=teams/manage_team&id=.
- risk 0.47cvss 7.2epss 0.05
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.05
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/admin/?page=reports&date=.
- risk 0.47cvss 7.2epss 0.01
ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/view_response&id=.
- risk 0.47cvss 7.2epss 0.01
ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/manage_response&id=.
- risk 0.47cvss 7.2epss 0.01
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id=
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_edit.php?booking=31&user_id=.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via Wedding-Management/wedding_details.php.