CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 554 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29680 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del. | ||
| CVE-2022-29676 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | ||
| CVE-2022-29670 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del. | ||
| CVE-2022-29666 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | ||
| CVE-2022-29665 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save. | ||
| CVE-2022-29663 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy. | ||
| CVE-2022-29662 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save. | ||
| CVE-2022-29661 | Hig | 0.47 | 7.2 | 0.01 | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save. | ||
| CVE-2022-30417 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-30415 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.php?id=. | ||
| CVE-2022-30414 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=applications/view_application&id=. | ||
| CVE-2022-30412 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.php?id=. | ||
| CVE-2022-30411 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=. | ||
| CVE-2022-30404 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=. | ||
| CVE-2022-30403 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=products&c=. | ||
| CVE-2022-30402 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=. | ||
| CVE-2022-30401 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=. | ||
| CVE-2022-30400 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=. | ||
| CVE-2022-30399 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=. | ||
| CVE-2022-30398 | Hig | 0.47 | 7.2 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=. |
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.
- risk 0.47cvss 7.2epss 0.01
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.
- risk 0.47cvss 7.2epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.php?id=.
- risk 0.47cvss 7.2epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=applications/view_application&id=.
- risk 0.47cvss 7.2epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.php?id=.
- risk 0.47cvss 7.2epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=.
- risk 0.47cvss 7.2epss 0.01
College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=products&c=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.
- risk 0.47cvss 7.2epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.