CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,889 vulnerabilities with CWE-89
CVE-2018-11309 CRITICAL
MemberMouse < 2.2.8 - Unauthenticated Blind SQL Injection via Coupon Code Parameter
CVSS 9.8
CVE-2018-11515 CRITICAL
wpForo < 1.4.5 - SQL Injection via Forum Search Parameter
CVSS 9.8
CVE-2018-6410 CRITICAL
MachForm - SQL Injection via Download Page q Parameter
CVSS 9.8
CVE-2018-10350 HIGH
Trend Micro Smart Protection Server (Standalone) 3.x - SQL Injection
CVSS 8.8
CVE-2018-11470 HIGH
iScripts eSwap 2.4 - SQL Injection via User Panel Search Told Parameter
CVSS 8.8
CVE-2018-11444 CRITICAL
EasyService Billing 1.0 - SQL Injection via jobcard-ongoing.php q Parameter
CVSS 9.8
CVE-2018-11414 HIGH
BearAdmin 0.5 - SQL Injection via Admin Log User ID Parameter
CVSS 8.8
CVE-2018-10595 MEDIUM
ReadA <1.1.0.2 - Privilege Escalation
CVSS 6.3
CVE-2018-10593 MEDIUM
DB Manager <3.0.1.0 - Privilege Escalation
CVSS 5.6
CVE-2018-11231 HIGH
Divido - SQL Injection
CVSS 8.1
CVE-2018-10356 HIGH
Trend Micro Email Encryption Gateway 5.5 - RCE
CVSS 8.8
CVE-2018-10353 MEDIUM
Trend Micro Email Encryption Gateway 5.5 - SQL Injection
CVSS 6.5
CVE-2018-10352 HIGH
Trend Micro Email Encryption Gateway 5.5 - SQL Injection
CVSS 8.8
CVE-2018-10351 HIGH
Trend Micro Email Encryption Gateway 5.5 - SQL Injection
CVSS 8.8
CVE-2018-9019 CRITICAL
Dolibarr < 7.0.2 - SQL Injection via sortfield Parameter
CVSS 9.8
CVE-2018-10094 CRITICAL
Dolibarr < 7.0.2 - SQL Injection via Integer Parameter
CVSS 9.8
CVE-2018-6493 HIGH
HP Network Operations Management Ultimate 2017.07-2018.02 & Network Automation 10.00-10.50 - Remote SQL Injection
CVSS 8.8
CVE-2018-6494 MEDIUM
Micro Focus Service Manager 9.30-9.51 - SQL Injection
CVSS 5.4
CVE-2018-11373 CRITICAL
iScripts eSwap 2.4 - SQL Injection via User Panel ToId Parameter
CVSS 9.8
CVE-2018-11372 CRITICAL
iScripts eSwap 2.4 - SQL Injection via User Panel ToId Parameter
CVSS 9.8
CVE-2018-11369 CRITICAL
PbootCMS 1.0.9 - SQL Injection via ParserController.php scode Parameter
CVSS 9.8
CVE-2018-9250 HIGH
OpenEMR < 5.0.1.1 - Authenticated SQL Injection via newlistname Parameter
CVSS 8.8
CVE-2018-10759 CRITICAL
ProjectPier < 0.8.8 - Remote File Inclusion and SQL Injection via id Parameter
CVSS 9.8
CVE-2018-10738 HIGH
Nagios XI 5.2.0-5.2.9 - SQL Injection via admin/menuaccess.php chbKey1 Parameter
CVSS 7.2
CVE-2018-10737 HIGH
Nagios XI 5.2.0-5.2.9 - SQL Injection via Logbook Search Parameter
CVSS 7.2
Details
Vulnerabilities 19,889
Exploit Likelihood High