Fallos del tipo CWE-89

12.898 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2020-27229MEDIUMA number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonIEPSS 0.8%CVE-2023-25350HIGHFaveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity ofEPSS 0.8%CVE-2023-6305MEDIUMSourceCodester Free and Open Source Inventory Management System suppliar_data.php sql injectionEPSS 0.8%CVE-2023-27411HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.4). The affected applications is vulnerable to SQL injection. TEPSS 0.8%CVE-2023-43739CRITICALOnline Book Store Project v1.0 - Unauthenticated SQL Injection (SQLi)EPSS 0.8%CVE-2023-27463HIGHA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The audit log form of affected applications is vulnerable tEPSS 0.8%CVE-2023-5373HIGHSourceCodester Online Computer and Laptop Store Master.php register sql injectionEPSS 0.8%CVE-2023-44164CRITICALOnline Movie Ticket Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)EPSS 0.8%CVE-2023-44163CRITICALOnline Movie Ticket Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)EPSS 0.8%CVE-2022-43531HIGH Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SEPSS 0.8%CVE-2024-9986MEDIUMcode-projects Blood Bank Management System member_register.php sql injectionEPSS 0.8%CVE-2023-44166CRITICALOnline Movie Ticket Booking System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)EPSS 0.8%CVE-2024-51327CRITICALSQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL InjeEPSS 0.8%CVE-2022-46956HIGHDynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.pEPSS 0.8%CVE-2026-61781CRITICALpg_partman has privilege escalation through SQL injection in create_partition_time()EPSS 0.8%CVE-2023-33557HIGHFuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.EPSS 0.8%CVE-2024-4801MEDIUMKashipara College Management System submit_new_faculty.php sql injectionEPSS 0.8%CVE-2024-1523HIGHEC-WEB FS-EZViewer(Web) - SQL InjectionEPSS 0.8%CVE-2024-4807MEDIUMKashipara College Management System delete_user.php sql injectionEPSS 0.8%CVE-2023-6097CRITICALSQL Injection on ICSSolution ICS Business ManagerEPSS 0.8%