CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,295)
page 807 of 1,015| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2010-2674 | 0.03 | — | 0.01 | Jul 8, 2010 | SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action. | |||
| CVE-2010-2673 | 0.03 | — | 0.01 | Jul 8, 2010 | SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-2670 | 0.03 | — | 0.01 | Jul 8, 2010 | SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-1327 | 0.03 | — | 0.01 | Jul 6, 2010 | Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3. | |||
| CVE-2010-2624 | 0.03 | — | 0.01 | Jul 2, 2010 | Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php. | |||
| CVE-2010-2623 | 0.03 | — | 0.01 | Jul 2, 2010 | SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter. | |||
| CVE-2010-2622 | 0.03 | — | 0.01 | Jul 2, 2010 | SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | |||
| CVE-2010-2616 | 0.03 | — | 0.01 | Jul 2, 2010 | SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter. | |||
| CVE-2010-2611 | 0.03 | — | 0.01 | Jul 2, 2010 | SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |||
| CVE-2010-2610 | 0.03 | — | 0.01 | Jul 2, 2010 | Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php. | |||
| CVE-2010-2609 | 0.03 | — | 0.01 | Jul 2, 2010 | SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |||
| CVE-2010-2513 | 0.03 | — | 0.01 | Jun 28, 2010 | SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php. | |||
| CVE-2010-2512 | 0.03 | — | 0.01 | Jun 28, 2010 | SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2010-2511 | 0.03 | — | 0.01 | Jun 28, 2010 | SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter. | |||
| CVE-2010-2510 | 0.03 | — | 0.01 | Jun 28, 2010 | SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter. | |||
| CVE-2010-2508 | 0.03 | — | 0.01 | Jun 28, 2010 | SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter. | |||
| CVE-2010-2462 | 0.03 | — | 0.01 | Jun 25, 2010 | SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action. | |||
| CVE-2010-2461 | 0.03 | — | 0.01 | Jun 25, 2010 | SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter. | |||
| CVE-2010-2460 | 0.03 | — | 0.01 | Jun 25, 2010 | SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter. | |||
| CVE-2010-2459 | 0.03 | — | 0.01 | Jun 25, 2010 | SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter. |
- CVE-2010-2674Jul 8, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action.
- CVE-2010-2673Jul 8, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-2670Jul 8, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-1327Jul 6, 2010risk 0.03cvss —epss 0.01
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
- CVE-2010-2624Jul 2, 2010risk 0.03cvss —epss 0.01
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.
- CVE-2010-2623Jul 2, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.
- CVE-2010-2622Jul 2, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
- CVE-2010-2616Jul 2, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.
- CVE-2010-2611Jul 2, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
- CVE-2010-2610Jul 2, 2010risk 0.03cvss —epss 0.01
Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php.
- CVE-2010-2609Jul 2, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
- CVE-2010-2513Jun 28, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.
- CVE-2010-2512Jun 28, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2010-2511Jun 28, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.
- CVE-2010-2510Jun 28, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter.
- CVE-2010-2508Jun 28, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter.
- CVE-2010-2462Jun 25, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.
- CVE-2010-2461Jun 25, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.
- CVE-2010-2460Jun 25, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.
- CVE-2010-2459Jun 25, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.