Fallos del tipo CWE-89

12.903 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2022-1684—Cube Slider <= 1.2 - Admin+ SQLiEPSS 0.8%CVE-2022-1690—Note Press <= 0.1.10 - Admin+ SQLi via Bulk ActionsEPSS 0.8%CVE-2024-25227MEDIUMSQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escaEPSS 0.8%CVE-2026-48448HIGHAdobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)EPSS 0.8%CVE-2025-25388CRITICALA SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackersEPSS 0.8%CVE-2025-25389CRITICALA SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers tEPSS 0.8%CVE-2024-4893CRITICALDigiWin EasyFlow .NET - SQL InjectionEPSS 0.8%CVE-2025-25914CRITICALSQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameterEPSS 0.8%CVE-2022-44858HIGHAutomotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_pEPSS 0.8%CVE-2023-20211HIGHA vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications EPSS 0.8%CVE-2026-23627HIGHOpenEMR has SQL Injection in Immunization Search/ReportEPSS 0.8%CVE-2026-27634HIGHPiwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filterEPSS 0.8%CVE-2025-5578MEDIUMPHPGurukul Dairy Farm Shop Management System sales-report-details.php sql injectionEPSS 0.8%CVE-2022-48152CRITICALSQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parEPSS 0.8%CVE-2024-1971HIGHSurya2Developer Online Shopping System POST Parameter login.php sql injectionEPSS 0.8%CVE-2021-23276HIGHImproper Neutralization of Special Elements used in an SQL CommandEPSS 0.8%CVE-2024-0480HIGHTaokeyun HTTP POST Request Drs.php index sql injectionEPSS 0.8%CVE-2023-2366MEDIUMSourceCodester Faculty Evaluation System sql injectionEPSS 0.8%CVE-2022-29822CRITICALFeathers - Improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injectionEPSS 0.8%CVE-2026-9668MEDIUMSQL injection vulnerability in ZTE SCP productEPSS 0.8%