← Back
CWE-89

20,741 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,741)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pointofsales Project
1Pointofsales
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
1Bakeshop Inventory System Project
1Bakeshop Inventory System
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
1Curriculum Evaluation System Project
1Curriculum Evaluation System
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.
1Bsen Ordering Software Project
1Bsen Ordering Software
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].
1Library Management System Project
1Library Management System
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Library Management System 1.0 has SQL Injection via the "Search for Books" screen.
1School Event Management System Project
1School Event Management System
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
1Saltos
1Saltos
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
1Saltos
1Saltos
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
1K Iwi
1K Iwi
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.
1Neo
1Debun Pop
Nov 21, 2024
Nov 15, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail search.
1Centreon
1Centreon
Nov 21, 2024
Nov 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
1Centreon
1Centreon
Nov 21, 2024
Nov 14, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.
3Canonical
PostgresqlRedhat
3Enterprise Linux
PostgresqlUbuntu Linux
Nov 21, 2024
Nov 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL stat...Show more
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.Show less
1Laobancms
1Laobancms
Nov 21, 2024
Nov 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter.
1Cisco
1Integrated Management Controller
Nov 21, 2024
Nov 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of...Show more
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.Show less
1Dedecms
1Dedecms
Nov 21, 2024
Nov 7, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.
1Degraupublicidade
1Degraupublicidade
Nov 21, 2024
Nov 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Busca.aspx.cs in Degrau Publicidade e Internet Plataforma de E-commerce allows SQL Injection via the busca/ URI.
1Zohocorp
1Manageengine Opmanager
Nov 21, 2024
Nov 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
1S Cms
1S Cms
Nov 21, 2024
Nov 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
1Dkcms
1Dkcms
Nov 21, 2024
Oct 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.