CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 553 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30830 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\feature_edit.php. | ||
| CVE-2022-30829 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php. | ||
| CVE-2022-30828 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php. | ||
| CVE-2022-30827 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php. | ||
| CVE-2022-30826 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php. | ||
| CVE-2022-30825 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php. | ||
| CVE-2022-30823 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php. | ||
| CVE-2022-30818 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31. | ||
| CVE-2022-30799 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. | ||
| CVE-2022-30798 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. | ||
| CVE-2022-30795 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. | ||
| CVE-2022-30794 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. | ||
| CVE-2022-29689 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del. | ||
| CVE-2022-29688 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy. | ||
| CVE-2022-29687 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del. | ||
| CVE-2022-29686 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan. | ||
| CVE-2022-29684 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del. | ||
| CVE-2022-29683 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del. | ||
| CVE-2022-29682 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del. | ||
| CVE-2022-29681 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del. |
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\feature_edit.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php.
- risk 0.47cvss 7.2epss 0.01
Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.