CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 96 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33509 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2023 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection. | ||
| CVE-2023-33734 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2023 | BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | ||
| CVE-2023-33280 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | ||
| CVE-2023-33279 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | ||
| CVE-2023-33278 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection. | ||
| CVE-2023-2851 | Cri | 0.64 | 9.8 | 0.01 | May 25, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware also EOS when CVE-ID assigned. | ||
| CVE-2023-2064 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20. | ||
| CVE-2023-2045 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4. | ||
| CVE-2023-2750 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05. | ||
| CVE-2023-1508 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3. | ||
| CVE-2023-31752 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php. | ||
| CVE-2023-33361 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php. | ||
| CVE-2023-33338 | Cri | 0.64 | 9.8 | 0.04 | May 23, 2023 | Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter. | ||
| CVE-2023-31707 | Cri | 0.64 | 9.8 | 0.01 | May 19, 2023 | SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php. | ||
| CVE-2023-29985 | Cri | 0.64 | 9.8 | 0.01 | May 18, 2023 | Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability. | ||
| CVE-2023-30191 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2023 | PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent(). | ||
| CVE-2023-30189 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook(). | ||
| CVE-2023-27742 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login. | ||
| CVE-2023-31519 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php. | ||
| CVE-2023-30245 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2023 | SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file. |
- risk 0.64cvss 9.8epss 0.01
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.
- risk 0.64cvss 9.8epss 0.01
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
- risk 0.64cvss 9.8epss 0.01
In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
- risk 0.64cvss 9.8epss 0.01
In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware also EOS when CVE-ID assigned.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
- risk 0.64cvss 9.8epss 0.01
Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
- risk 0.64cvss 9.8epss 0.04
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
- risk 0.64cvss 9.8epss 0.01
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().
- risk 0.64cvss 9.8epss 0.01
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
- risk 0.64cvss 9.8epss 0.01
IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file.