Falhas do tipo CWE-89

12.895 resultados

Injeção de SQL

Fraqueza onde entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O banco de dados executa comandos não intencionais, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Exemplo

Um formulário de login concatena o usuário digitado direto na query: `SELECT * FROM users WHERE login = '` + input + `'`. Se o usuário digita `admin' OR '1'='1`, a query vira `SELECT * FROM users WHERE login = 'admin' OR '1'='1'`, retornando todos os usuários e burlando autenticação.

Como mitigar

Use prepared statements (consultas parametrizadas) com placeholders, nunca concatene entrada do usuário. Valide e restrinja entrada (whitelist), aplique princípio do menor privilégio na conta do BD e use WAF como camada adicional.

CVE-2022-1689—Note Press <= 0.1.10 - Admin+ SQLi via UpdateEPSS 0.8%CVE-2024-25227MEDIUMSQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escaEPSS 0.8%CVE-2026-48448HIGHAdobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)EPSS 0.8%CVE-2025-25388CRITICALA SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackersEPSS 0.8%CVE-2025-25389CRITICALA SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers tEPSS 0.8%CVE-2025-25914CRITICALSQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameterEPSS 0.8%CVE-2024-4893CRITICALDigiWin EasyFlow .NET - SQL InjectionEPSS 0.8%CVE-2022-44858HIGHAutomotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_pEPSS 0.8%CVE-2026-23627HIGHOpenEMR has SQL Injection in Immunization Search/ReportEPSS 0.8%CVE-2024-0480HIGHTaokeyun HTTP POST Request Drs.php index sql injectionEPSS 0.8%CVE-2023-20211HIGHA vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications EPSS 0.8%CVE-2022-48152CRITICALSQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parEPSS 0.8%CVE-2026-27634HIGHPiwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filterEPSS 0.8%CVE-2025-5578MEDIUMPHPGurukul Dairy Farm Shop Management System sales-report-details.php sql injectionEPSS 0.8%CVE-2021-23276HIGHImproper Neutralization of Special Elements used in an SQL CommandEPSS 0.8%CVE-2024-1971HIGHSurya2Developer Online Shopping System POST Parameter login.php sql injectionEPSS 0.8%CVE-2023-1300MEDIUMSourceCodester COVID 19 Testing Management System POST Parameter patient-report.php sql injectionEPSS 0.8%CVE-2023-2366MEDIUMSourceCodester Faculty Evaluation System sql injectionEPSS 0.8%CVE-2022-29822CRITICALFeathers - Improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injectionEPSS 0.8%CVE-2023-1301MEDIUMSourceCodester Friendly Island Pizza Website and Ordering System GET Parameter deleteorder.php sql injectionEPSS 0.8%