← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.)
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
1Zzcms
1Zzcms
Nov 21, 2024
Oct 29, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.)
1Phptpoint
1Hospital Management System
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php.
1Phptpoint
1Pharmacy Management System
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
1Icmsdev
1Icms
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.
1Projectsend
1Projectsend
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, cl...Show more
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.Show less
1Nedap
1Mysql Binuuid Rails
Nov 21, 2024
Oct 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
1Citrix
2Netscaler Sd Wan
Sd Wan
Nov 21, 2024
Oct 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
1Serverscheck
1Serverscheck
Nov 21, 2024
Oct 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.
1Thinkphp
1Thinkphp
Nov 21, 2024
Oct 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.
1Thinkphp
1Thinkphp
Nov 21, 2024
Oct 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.
1Thinkphp
1Thinkphp
Nov 21, 2024
Oct 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.
1Owndms
1Ownticket
Nov 21, 2024
Oct 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.