CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,866 vulnerabilities with CWE-89
CVE-2018-20018 HIGH
S-CMS V3.0 - SQL Injection via S_id Parameter
CVSS 7.5
CVE-2018-7065 HIGH
Aruba ClearPass Policy Manager < 6.6.10 - Authenticated SQL Injection
CVSS 7.2
CVE-2018-19925 CRITICAL
Sales & Company Management System < 2018-06-06 - SQL Injection via Member Order Type Parameter
CVSS 9.8
CVE-2018-19898 HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via Article Edit Post Parameter
CVSS 8.8
CVE-2018-19897 HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via listorders[key][1] Parameter
CVSS 7.2
CVE-2018-19896 HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via SlideController ids[] Parameter
CVSS 7.2
CVE-2018-19895 HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via parentid Parameter in Nav Action
CVSS 7.2
CVE-2018-19894 HIGH
ThinkCMF X2.2.2 - Authenticated SQL Injection via CommentadminController ids[] Parameter
CVSS 7.2
CVE-2018-19893 CRITICAL
PbootCMS 1.2.1 - SQL Injection via SearchController.php Query String
CVSS 9.8
CVE-2018-1002000 HIGH
WordPress Arigato Autoresponder & Newsletter <v2.5.1.8 - SQL Injection
CVSS 7.2
CVE-2018-18619 CRITICAL
Advanced Comment System 1.0 - SQL Injection via Page Parameter
CVSS 9.8
CVE-2018-15441 CRITICAL
Cisco Prime License Manager 11.0.1-11.5 - Unauthenticated SQL Injection via HTTP POST Request
CVSS 9.4
CVE-2018-13350 CRITICAL
TerraMaster TOS 3.1.03 - SQL Injection via Event Parameter
CVSS 9.8
CVE-2018-18982 HIGH
NUUO CMS < 3.3 - SQL Injection
CVSS 8.8
CVE-2018-19559 CRITICAL
CuppaCMS <2018-11-12 - SQL Injection
CVSS 9.8
CVE-2018-19558 CRITICAL
arcms < 2018-03-19 - SQL Injection via Newslist Limit Parameter
CVSS 9.8
CVE-2018-19557 CRITICAL
arcms <2018-03-19 - Info Disclosure
CVSS 9.8
CVE-2018-19553 HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19552 HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19551 HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19549 HIGH
Interspire Email Marketer <6.1.6 - SQL Injection
CVSS 8.8
CVE-2018-19468 CRITICAL
HuCart 5.7.4 - SQL Injection via X-Forwarded-For Header
CVSS 9.8
CVE-2018-19436 HIGH
webERP 4.15 - SQL Injection via Manufacturing CollectiveWorkOrderCost.php SearchParts Parameter
CVSS 7.2
CVE-2018-19435 HIGH
webERP 4.15 - SQL Injection via SalesInquiry.php SortBy Parameter
CVSS 7.2
CVE-2018-19434 HIGH
webERP 4.15 - SQL Injection via BankMatching.php AmtClear_ Parameter
CVSS 7.2
Details
Vulnerabilities 19,866
Exploit Likelihood High