Falhas do tipo CWE-89

12.922 resultados

Injeção de SQL

Fraqueza onde entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O banco de dados executa comandos não intencionais, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Exemplo

Um formulário de login concatena o usuário digitado direto na query: `SELECT * FROM users WHERE login = '` + input + `'`. Se o usuário digita `admin' OR '1'='1`, a query vira `SELECT * FROM users WHERE login = 'admin' OR '1'='1'`, retornando todos os usuários e burlando autenticação.

Como mitigar

Use prepared statements (consultas parametrizadas) com placeholders, nunca concatene entrada do usuário. Valide e restrinja entrada (whitelist), aplique princípio do menor privilégio na conta do BD e use WAF como camada adicional.

CVE-2024-3442MEDIUMSourceCodester Prison Management System delete_leave.php sql injectionEPSS 0.7%CVE-2024-3466MEDIUMSourceCodester Laundry Management System Pengeluaran.php laporan_filter sql injectionEPSS 0.7%CVE-2023-1407MEDIUMSourceCodester Student Study Center Desk Management System manage_user.php sql injectionEPSS 0.7%CVE-2026-67854CRITICALSQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary codeEPSS 0.7%CVE-2024-3224MEDIUMSourceCodester PHP Task Management System task-details.php sql injectionEPSS 0.7%CVE-2023-1091CRITICALSQL Injection found in ALPATA's Licensed Warehousing Automation SystemEPSS 0.7%CVE-2022-38492HIGHAn issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes theEPSS 0.7%CVE-2022-38490CRITICALAn issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 correctsEPSS 0.7%CVE-2024-0359HIGHcode-projects Simple Online Hotel Reservation System login.php sql injectionEPSS 0.7%CVE-2023-6903HIGHNetentsec NS-ASG Application Security Gateway sql injectionEPSS 0.7%CVE-2023-2962MEDIUMSourceCodester Faculty Evaluation System sql injectionEPSS 0.7%CVE-2023-5804HIGHPHPGurukul Nipah Virus Testing Management System login.php sql injectionEPSS 0.7%CVE-2024-0287MEDIUMKashipara Food Management System itemBillPdf.php sql injectionEPSS 0.7%CVE-2022-44120CRITICALdedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.EPSS 0.7%CVE-2023-5794HIGHPHPGurukul Online Railway Catering System Login index.php sql injectionEPSS 0.7%CVE-2024-0655MEDIUMNovel-Plus list sql injectionEPSS 0.7%CVE-2023-5828HIGHNanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System login.aspx sql injectionEPSS 0.7%CVE-2023-1366MEDIUMSourceCodester Yoga Class Registration System manage_category.php query sql injectionEPSS 0.7%CVE-2024-25216CRITICALEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.EPSS 0.7%CVE-2023-24812HIGHSQL injection of notes/search-by-tagEPSS 0.7%