CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,889 vulnerabilities with CWE-89
CVE-2018-14066 CRITICAL
Android - SQL Injection via wappush Content Provider
CVSS 9.8
CVE-2018-14012 CRITICAL
WolfSight CMS 3.2 - SQL Injection via PATH_INFO
CVSS 9.8
CVE-2018-10197 CRITICAL
ELO ELOenterprise/ELOprofessional <10.18.040 - SQL Injection
CVSS 9.8
CVE-2018-13850 CRITICAL
Firebase Cloud Messaging + Advance Admin Panel < 2017-10-26 - SQL Injection via Login Username Parameter
CVSS 9.8
CVE-2018-12977 HIGH
SoftExpert Excellence Suite 2.0 - Authenticated SQL Injection via cddocument Parameter
CVSS 8.8
CVE-2018-13450 CRITICAL
Dolibarr 7.0.3 - SQL Injection via Status Batch Parameter
CVSS 9.8
CVE-2018-13449 CRITICAL
Dolibarr ERP/CRM 7.0.3 - SQL Injection via statut_buy Parameter
CVSS 9.8
CVE-2018-13448 CRITICAL
Dolibarr 7.0.3 - SQL Injection via country_id Parameter
CVSS 9.8
CVE-2018-13447 CRITICAL
Dolibarr ERP/CRM 7.0.3 - SQL Injection via statut Parameter
CVSS 9.8
CVE-2018-3754 HIGH
query-mysql 0.0.0-0.0.2 - SQL Injection
CVSS 8.8
CVE-2018-13116 CRITICAL
zzcms 8.3 - SQL Injection via tablename Parameter
CVSS 9.8
CVE-2018-11643 HIGH
Dialogic PowerMedia XMS <= 3.5 - Authenticated SQL Injection via filterPattern Parameter
CVSS 8.8
CVE-2018-7774 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7773 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7772 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7769 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7768 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7767 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7766 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-7765 HIGH
Schneider Electric U.motion Builder <1.3.4 - SQL Injection
CVSS 8.8
CVE-2018-13050 CRITICAL
Zoho ManageEngine Applications Manager 13.x < 13800 - SQL Injection via j_username Parameter
CVSS 9.8
CVE-2018-13049 HIGH
GLPI 9.2.0-9.3.0 - SQL Injection via LIMIT Clause in Computer Search
CVSS 8.8
CVE-2018-12464 CRITICAL
Micro Focus Secure Messaging Gateway <471 - SQL Injection
CVSS 10.0
CVE-2018-12912 HIGH
HongCMS 3.0.0 - SQL Injection via Database Empty Table URI Parameter
CVSS 7.2
CVE-2018-1000558 MEDIUM
OCS Inventory NG ocsreports <2.4.1 - SQL Injection
CVSS 6.5
Details
Vulnerabilities 19,889
Exploit Likelihood High