CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 68 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-33806 | Cri | 0.64 | 9.8 | 0.01 | May 28, 2024 | A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | ||
| CVE-2024-33805 | Cri | 0.64 | 9.8 | 0.01 | May 28, 2024 | A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | ||
| CVE-2024-33801 | Cri | 0.64 | 9.8 | 0.01 | May 28, 2024 | A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | ||
| CVE-2024-33800 | Cri | 0.64 | 9.8 | 0.01 | May 28, 2024 | A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter. | ||
| CVE-2024-33799 | Cri | 0.64 | 9.8 | 0.01 | May 28, 2024 | A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter. | ||
| CVE-2024-35091 | — | Cri | 0.64 | 9.8 | 0.00 | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml. | |
| CVE-2024-35086 | — | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml . | |
| CVE-2024-35084 | — | Cri | 0.64 | 9.8 | 0.00 | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml. | |
| CVE-2024-34935 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter. | ||
| CVE-2024-34934 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter. | ||
| CVE-2024-34932 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter. | ||
| CVE-2024-34931 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter. | ||
| CVE-2024-34929 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index parameter. | ||
| CVE-2024-34927 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter. | ||
| CVE-2023-51637 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2024 | Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG. Authentication is not required to exploit this vulnerability. The… | ||
| CVE-2024-35409 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2024 | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. | ||
| CVE-2024-35056 | Cri | 0.64 | 9.8 | 0.01 | May 21, 2024 | NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions. | ||
| CVE-2024-35361 | Cri | 0.64 | 9.8 | 0.01 | May 21, 2024 | MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights. | ||
| CVE-2024-4609 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2024 | A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack… | ||
| CVE-2024-4992 | Cri | 0.64 | 9.8 | 0.00 | May 16, 2024 | Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it. |
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
- risk 0.64cvss 9.8epss 0.00
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.
- risk 0.64cvss 9.8epss 0.01
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .
- risk 0.64cvss 9.8epss 0.00
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index parameter.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.
- risk 0.64cvss 9.8epss 0.01
Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG. Authentication is not required to exploit this vulnerability. The…
- risk 0.64cvss 9.8epss 0.01
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
- risk 0.64cvss 9.8epss 0.01
NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.
- risk 0.64cvss 9.8epss 0.01
MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.
- risk 0.64cvss 9.8epss 0.01
A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack…
- risk 0.64cvss 9.8epss 0.00
Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.