CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 61 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43773 | Cri | 0.64 | 9.8 | 0.00 | Sep 2, 2024 | SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter. | ||
| CVE-2024-43772 | Cri | 0.64 | 9.8 | 0.00 | Sep 2, 2024 | SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter. | ||
| CVE-2024-41372 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php. | ||
| CVE-2024-41370 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php. | ||
| CVE-2024-29731 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/… | ||
| CVE-2024-29730 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ ,… | ||
| CVE-2024-29729 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/,… | ||
| CVE-2024-29728 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ ,… | ||
| CVE-2024-29727 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRe… | ||
| CVE-2024-29726 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/,… | ||
| CVE-2024-29725 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/,… | ||
| CVE-2024-29724 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter… | ||
| CVE-2024-29723 | Cri | 0.64 | 9.8 | 0.00 | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/,… | ||
| CVE-2024-44761 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2024 | An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests. | ||
| CVE-2024-7071 | Cri | 0.64 | 9.8 | 0.00 | Aug 27, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection. This issue affects Brain Low-Code: before 2.1.0. | ||
| CVE-2024-45265 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2024 | A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter. | ||
| CVE-2024-42913 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2024 | RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1. | ||
| CVE-2024-41444 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2024 | SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so. | ||
| CVE-2024-8161 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2024 | SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information… | ||
| CVE-2024-42765 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2024 | A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters. |
- risk 0.64cvss 9.8epss 0.00
SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.
- risk 0.64cvss 9.8epss 0.00
SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.
- risk 0.64cvss 9.8epss 0.01
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.
- risk 0.64cvss 9.8epss 0.01
Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ ,…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/,…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ ,…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRe…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/,…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/,…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter…
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/,…
- risk 0.64cvss 9.8epss 0.01
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
- risk 0.64cvss 9.8epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection. This issue affects Brain Low-Code: before 2.1.0.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.
- risk 0.64cvss 9.8epss 0.00
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
- risk 0.64cvss 9.8epss 0.00
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information…
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters.