CWE-89
20,741 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,741)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pointofsales Project 1Pointofsales Nov 21, 2024 Nov 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. |
1Bakeshop Inventory System Project 1Bakeshop Inventory System Nov 21, 2024 Nov 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. |
1Curriculum Evaluation System Project 1Curriculum Evaluation System Nov 21, 2024 Nov 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. |
1Bsen Ordering Software Project 1Bsen Ordering Software Nov 21, 2024 Nov 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL]. |
1Library Management System Project 1Library Management System Nov 21, 2024 Nov 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Library Management System 1.0 has SQL Injection via the "Search for Books" screen. |
1School Event Management System Project 1School Event Management System Nov 21, 2024 Nov 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. |
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection. |
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection. |
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter. |
SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search. |
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection. |
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter. |
3Canonical PostgresqlRedhat3Enterprise Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL stat...Show more |
An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter. |
1Cisco 1Integrated Management Controller Nov 21, 2024 Nov 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of...Show more |
DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter. |
1Degraupublicidade 1Degraupublicidade Nov 21, 2024 Nov 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Busca.aspx.cs in Degrau Publicidade e Internet Plataforma de E-commerce allows SQL Injection via the busca/ URI. |
1Zohocorp 1Manageengine Opmanager Nov 21, 2024 Nov 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings. |
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field). |
admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp. |