CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 81 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-51048 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2023 | S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php. | ||
| CVE-2023-6145 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection. This issue affects Softomi Advanced C2C Marketplace… | ||
| CVE-2023-48434 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-48433 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-47990 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter. | ||
| CVE-2023-48384 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database. | ||
| CVE-2023-48372 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database. | ||
| CVE-2023-48050 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the… | ||
| CVE-2023-48049 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2023 | A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component. | ||
| CVE-2023-50563 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php. | ||
| CVE-2023-50073 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. | ||
| CVE-2023-49708 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQLi vulnerability in Starshop component for Joomla. | ||
| CVE-2023-49707 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQLi vulnerability in S5 Register module for Joomla. | ||
| CVE-2023-48925 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run(). | ||
| CVE-2023-46348 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods. | ||
| CVE-2023-40629 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQLi vulnerability in LMS Lite component for Joomla. | ||
| CVE-2023-49934 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1. | ||
| CVE-2023-40921 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2023 | SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters. | ||
| CVE-2023-49363 | Cri | 0.64 | 9.8 | 0.01 | Dec 13, 2023 | Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php. | ||
| CVE-2023-5008 | Cri | 0.64 | 9.8 | 0.01 | Dec 8, 2023 | Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control. |
- risk 0.64cvss 9.8epss 0.01
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection. This issue affects Softomi Advanced C2C Marketplace…
- risk 0.64cvss 9.8epss 0.01
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.
- risk 0.64cvss 9.8epss 0.01
ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
- risk 0.64cvss 9.8epss 0.01
ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the…
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.
- risk 0.64cvss 9.8epss 0.01
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
- risk 0.64cvss 9.8epss 0.01
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
- risk 0.64cvss 9.8epss 0.01
SQLi vulnerability in Starshop component for Joomla.
- risk 0.64cvss 9.8epss 0.01
SQLi vulnerability in S5 Register module for Joomla.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().
- risk 0.64cvss 9.8epss 0.01
SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.
- risk 0.64cvss 9.8epss 0.01
SQLi vulnerability in LMS Lite component for Joomla.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.
- risk 0.64cvss 9.8epss 0.01
Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.
- risk 0.64cvss 9.8epss 0.01
Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.