CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 93 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34477 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-34476 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-23758 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-23757 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | ||
| CVE-2023-33367 | Cri | 0.64 | 9.8 | 0.01 | Aug 5, 2023 | A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution. | ||
| CVE-2023-39551 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php. | ||
| CVE-2023-33665 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. | ||
| CVE-2023-33666 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php. | ||
| CVE-2023-36213 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function. | ||
| CVE-2023-38954 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2023-39122 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200). | ||
| CVE-2023-37771 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php. | ||
| CVE-2020-21662 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF. | ||
| CVE-2023-37647 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php. | ||
| CVE-2023-26859 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2023 | SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component. | ||
| CVE-2023-35066 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701. | ||
| CVE-2023-3046 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection. This issue affects Scienta: before 20230630.1953. | ||
| CVE-2023-31753 | Cri | 0.64 | 9.8 | 0.01 | Jul 20, 2023 | SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter. | ||
| CVE-2023-37165 | Cri | 0.64 | 9.8 | 0.02 | Jul 20, 2023 | Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php. | ||
| CVE-2023-30153 | Cri | 0.64 | 9.8 | 0.01 | Jul 18, 2023 | An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller. |
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.
- risk 0.64cvss 9.8epss 0.01
PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.
- risk 0.64cvss 9.8epss 0.01
ai-dev aitable before v0.2.2 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
- risk 0.64cvss 9.8epss 0.01
ai-dev aioptimizedcombinations before v0.1.3 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.
- risk 0.64cvss 9.8epss 0.01
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.
- risk 0.64cvss 9.8epss 0.01
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection. This issue affects Scienta: before 20230630.1953.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.
- risk 0.64cvss 9.8epss 0.02
Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.
- risk 0.64cvss 9.8epss 0.01
An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller.