CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 99 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36972 | Cri | 0.64 | 9.8 | 0.07 | Mar 29, 2023 | This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An… | ||
| CVE-2023-27847 | Cri | 0.64 | 9.8 | 0.05 | Mar 27, 2023 | SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components. | ||
| CVE-2023-26959 | Cri | 0.64 | 9.8 | 0.01 | Mar 27, 2023 | Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter. | ||
| CVE-2023-28437 | Cri | 0.64 | 9.8 | 0.01 | Mar 25, 2023 | Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds. | ||
| CVE-2023-26864 | Cri | 0.64 | 9.8 | 0.01 | Mar 24, 2023 | SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent. | ||
| CVE-2023-1050 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10. | ||
| CVE-2023-24655 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function. | ||
| CVE-2023-27638 | Cri | 0.64 | 9.8 | 0.03 | Mar 22, 2023 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions… | ||
| CVE-2023-27637 | Cri | 0.64 | 9.8 | 0.03 | Mar 22, 2023 | An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could… | ||
| CVE-2023-27570 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie. | ||
| CVE-2023-27569 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header. | ||
| CVE-2023-1153 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22. | ||
| CVE-2023-26905 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id. | ||
| CVE-2023-1152 | Cri | 0.64 | 9.8 | 0.01 | Mar 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93. | ||
| CVE-2023-27041 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php. | ||
| CVE-2023-27250 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php. | ||
| CVE-2023-26784 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter. | ||
| CVE-2023-24726 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page. | ||
| CVE-2023-27074 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page. | ||
| CVE-2023-27052 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2023 | E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php. |
- risk 0.64cvss 9.8epss 0.07
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An…
- risk 0.64cvss 9.8epss 0.05
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.
- risk 0.64cvss 9.8epss 0.01
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.
- risk 0.64cvss 9.8epss 0.01
Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10.
- risk 0.64cvss 9.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could…
- risk 0.64cvss 9.8epss 0.01
The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.
- risk 0.64cvss 9.8epss 0.01
The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pacsrapor allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Pacsrapor: before 1.22.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affects Persolus: before 2.03.93.
- risk 0.64cvss 9.8epss 0.01
School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php.
- risk 0.64cvss 9.8epss 0.01
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.
- risk 0.64cvss 9.8epss 0.01
BP Monitoring Management System v1.0 was discovered to contain a SQL injection vulnerability via the emailid parameter in the login page.
- risk 0.64cvss 9.8epss 0.01
E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php.