CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,387)
page 798 of 1,020| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2010-5055 | 0.03 | — | 0.02 | Nov 23, 2011 | SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-5053 | 0.03 | — | 0.02 | Nov 23, 2011 | SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php. | |||
| CVE-2010-5047 | 0.03 | — | 0.02 | Nov 23, 2011 | SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2011-4066 | 0.03 | — | 0.02 | Nov 4, 2011 | SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO. | |||
| CVE-2010-5044 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. … | |||
| CVE-2010-5043 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php. | |||
| CVE-2010-5041 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action. | |||
| CVE-2010-5039 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information. | |||
| CVE-2010-5037 | 0.03 | — | 0.02 | Nov 2, 2011 | SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | |||
| CVE-2010-5036 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. | |||
| CVE-2010-5034 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter. | |||
| CVE-2010-5033 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter. | |||
| CVE-2010-5032 | 0.03 | — | 0.02 | Nov 2, 2011 | SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php. | |||
| CVE-2010-5029 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action. | |||
| CVE-2010-5026 | 0.03 | — | 0.02 | Nov 2, 2011 | SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information. | |||
| CVE-2010-5024 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information. | |||
| CVE-2010-5023 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter. | |||
| CVE-2010-5022 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php. | |||
| CVE-2010-5021 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter. | |||
| CVE-2010-5020 | 0.03 | — | 0.01 | Nov 2, 2011 | SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. |
- CVE-2010-5055Nov 23, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-5053Nov 23, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php.
- CVE-2010-5047Nov 23, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2011-4066Nov 4, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
- CVE-2010-5044Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remote authenticated users, with Public Back-end privileges, to execute arbitrary SQL commands via the search parameter in a log action to administrator/index.php. …
- CVE-2010-5043Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the cid[] parameter in an editItem action to administrator/index.php.
- CVE-2010-5041Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.
- CVE-2010-5039Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.
- CVE-2010-5037Nov 2, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
- CVE-2010-5036Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
- CVE-2010-5034Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbitrary SQL commands via the planid parameter.
- CVE-2010-5033Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL commands via the CatDisplay parameter.
- CVE-2010-5032Nov 2, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php.
- CVE-2010-5029Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the show parameter in a web action.
- CVE-2010-5026Nov 2, 2011risk 0.03cvss —epss 0.02
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.
- CVE-2010-5024Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.
- CVE-2010-5023Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.
- CVE-2010-5022Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.
- CVE-2010-5021Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intGroupID parameter.
- CVE-2010-5020Nov 2, 2011risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.