CWE-89
20,856 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,856)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQ...Show more |
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests....Show more |
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page. |
1Itechscripts 1Auction Script Nov 21, 2024 Jul 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in Itech Auction Script 6.49. It has been classified as critical. This affects an unknown part of the file /mcategory.php. The manipulation of the argument mcid with the input 4' AND 1734=1734 A...Show more |
A vulnerability was found in Itech B2B Script 4.28. It has been rated as critical. This issue affects some unknown processing of the file /catcompany.php. The manipulation of the argument token with the input 704667c6a1e...Show more |
1Itechscripts 1Classifieds Script Nov 21, 2024 Jul 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AN...Show more |
A vulnerability classified as critical was found in Itech Dating Script 3.26. Affected by this vulnerability is an unknown functionality of the file /see_more_details.php. The manipulation of the argument id leads to sql...Show more |
A vulnerability, which was classified as critical, has been found in Itech Freelancer Script 5.13. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument sk leads...Show more |
1Itechscripts 1Multi Vendor Script Nov 21, 2024 Jul 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in Itech Multi Vendor Script 6.49 and classified as critical. This issue affects some unknown processing of the file /multi-vendor-shopping-script/product-list.php. The manipulation of the argum...Show more |
1Itechscripts 1News Portal Script Nov 21, 2024 Jul 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipulation of the argument inf leads to sql...Show more |
1Itechscripts 1Real Estate Script Nov 21, 2024 Jul 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-script/search_property.php. The manipulati...Show more |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jul 14, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product. |
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jul 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=. |
Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function. |
1Fahou100 1Electronic Mall System Jun 17, 2026 Jul 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection. |
A vulnerability was found in LogoStore. It has been classified as critical. Affected is an unknown function of the file /LogoStore/search.php. The manipulation of the argument query with the input test' UNION ALL SELECT...Show more |
1Kb Messages Php Script Project 1Kb Messages Php Script Nov 21, 2024 Jul 13, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''...Show more |
1Kb Login Authentication Script Project 1Kb Login Authentication Script Nov 21, 2024 Jul 13, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in KB Login Authentication Script 1.1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument username/password with the input 'or''='...Show more |
1Kb Affiliate Referral Script Project 1Kb Affiliate Referral Script Nov 21, 2024 Jul 13, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in KB Affiliate Referral Script 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument username/password with the input 'o...Show more |
1In2code 1Living User Experience Jun 17, 2026 Jul 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3. |