CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 69 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-4991 | Cri | 0.64 | 9.8 | 0.00 | May 16, 2024 | Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it. | ||
| CVE-2024-4826 | Cri | 0.64 | 9.8 | 0.00 | May 16, 2024 | SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id… | ||
| CVE-2024-34955 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2024 | Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter. | ||
| CVE-2024-4893 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2024 | DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands. | ||
| CVE-2024-33485 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component | ||
| CVE-2024-34256 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | ||
| CVE-2024-4824 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL… | ||
| CVE-2024-25532 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx. | ||
| CVE-2024-31961 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbitrary SQL commands via the level2 parameter. | ||
| CVE-2024-25531 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx. | ||
| CVE-2024-25530 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx. | ||
| CVE-2024-25529 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx. | ||
| CVE-2024-25525 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx. | ||
| CVE-2024-25523 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx. | ||
| CVE-2024-25520 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx. | ||
| CVE-2024-25519 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx. | ||
| CVE-2024-25517 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx. | ||
| CVE-2024-25510 | Cri | 0.64 | 9.8 | 0.01 | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aspx. | ||
| CVE-2024-25508 | Cri | 0.64 | 9.8 | 0.01 | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx. | ||
| CVE-2024-33164 | — | Cri | 0.64 | 9.8 | 0.01 | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function. |
- risk 0.64cvss 9.8epss 0.00
Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id…
- risk 0.64cvss 9.8epss 0.01
Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
- risk 0.64cvss 9.8epss 0.01
DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component
- risk 0.64cvss 9.8epss 0.01
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.
- risk 0.64cvss 9.8epss 0.01
Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL…
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbitrary SQL commands via the level2 parameter.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlow/OfficeFileDownload.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aspx.
- risk 0.64cvss 9.8epss 0.01
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aspx.
- risk 0.64cvss 9.8epss 0.01
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.