CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 62 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42784 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2024 | A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter. | ||
| CVE-2024-42783 | Cri | 0.64 | 9.8 | 0.00 | Aug 21, 2024 | Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter. | ||
| CVE-2024-42782 | Cri | 0.64 | 9.8 | 0.00 | Aug 21, 2024 | A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter. | ||
| CVE-2024-42781 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2024 | A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter. | ||
| CVE-2024-33872 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2024 | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges. | ||
| CVE-2024-42575 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php. | ||
| CVE-2024-42574 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php. | ||
| CVE-2024-42573 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php. | ||
| CVE-2024-42572 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php. | ||
| CVE-2024-42571 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php. | ||
| CVE-2024-42570 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php. | ||
| CVE-2024-42569 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php. | ||
| CVE-2024-42568 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php. | ||
| CVE-2024-42567 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2. | ||
| CVE-2024-42566 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php | ||
| CVE-2024-42565 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete. | ||
| CVE-2024-42562 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php. | ||
| CVE-2024-42558 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php. | ||
| CVE-2024-42556 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php. | ||
| CVE-2024-6847 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot. |
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.
- risk 0.64cvss 9.8epss 0.00
Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.
- risk 0.64cvss 9.8epss 0.00
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.
- risk 0.64cvss 9.8epss 0.00
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
- risk 0.64cvss 9.8epss 0.01
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.
- risk 0.64cvss 9.8epss 0.01
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.
- risk 0.64cvss 9.8epss 0.01
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.
- risk 0.64cvss 9.8epss 0.01
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.