CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,889 vulnerabilities with CWE-89
CVE-2018-1282 CRITICAL
Apache Hive JDBC Driver 0.7.1-2.3.2 - SQL Injection via PreparedStatement Argument Bypass
CVSS 9.1
CVE-2018-9309 CRITICAL
zzcms 8.2 - SQL Injection via dl/dl_sendsms.php id Parameter
CVSS 9.8
CVE-2018-9247 CRITICAL
Gxlcms QY v1.0.0713 - SQL Injection via upsql Function
CVSS 9.8
CVE-2018-9230 CRITICAL
OpenResty < 1.13.6.1 - Parameter Overflow Bypass via URI Parameter Handling
CVSS 9.8
CVE-2018-8820 HIGH
Square 9 GlobalForms 6.2.x - SQL Injection
CVSS 7.5
CVE-2018-8802 HIGH
Unisys ClearPath ePortal Manager < 17.0a.31 and ePortal-2200 < 2.2.81 - SQL Injection
CVSS 8.1
CVE-2018-8967 CRITICAL
zzcms 8.2 - SQL Injection via adv2.php id Parameter
CVSS 9.8
CVE-2018-8943 CRITICAL
PHPSHE 1.6 - SQL Injection via Userbank Parameter
CVSS 9.8
CVE-2018-7528 CRITICAL
Geutebruck G-Cam/EFD-2250 and TopFD-2125 - SQL Injection
CVSS 9.1
CVE-2018-7269 CRITICAL
Yii 2.0.0-2.0.14 - SQL Injection via findByCondition in ActiveRecord
CVSS 9.8
CVE-2018-6843 HIGH
Kentico Xperience 10.0-10.0.50 - Authenticated SQL Injection
CVSS 7.2
CVE-2018-7033 CRITICAL
SchedMD Slurm < 17.02.10 and 17.11.x < 17.11.5 - SQL Injection
CVSS 9.8
CVE-2018-6230 MEDIUM
Trend Micro Email Encryption Gateway 5.5 - SQL Injection via Search Configuration Script
CVSS 6.8
CVE-2018-6229 CRITICAL
Trend Micro Email Encryption Gateway 5.5 - SQL Injection via Edit Policy Script
CVSS 9.8
CVE-2018-6228 CRITICAL
Trend Micro Email Encryption Gateway 5.5 - SQL Injection via Policy Script
CVSS 9.8
CVE-2018-8045 HIGH
Joomla! 3.5.0-3.8.5 - SQL Injection in User Notes List View
CVSS 8.8
CVE-2018-6329 CRITICAL
Unitrends Backup < 10.1.10 - SQL Injection and Remote Code Execution via Authentication Bypass
CVSS 9.8
CVE-2018-7474 CRITICAL
Textpattern < 4.6.2 - SQL Injection via qty Parameter
CVSS 9.8
CVE-2018-1000131 CRITICAL
WP Support Plus Responsive Ticket System < 9.0.2 - Unauthenticated SQL Injection via Email Cookie Parameter
CVSS 9.8
CVE-2018-7538 CRITICAL
Tuleap < 9.18 - SQL Injection in Tracker Functionality
CVSS 9.8
CVE-2018-8057 CRITICAL
Western Bridge Cobub Razor 0.8.0 - SQL Injection
CVSS 9.8
CVE-2018-7735 HIGH
Afian FileRun <2018.02.13 - SQL Injection
CVSS 7.2
CVE-2018-7734 HIGH
Afian FileRun <2018.02.13 - SQL Injection
CVSS 7.2
CVE-2018-7732 CRITICAL
YxtCMF < 3.1 - SQL Injection via ShitiController ids Parameter
CVSS 9.8
CVE-2018-7666 CRITICAL
ClipBucket < 4.0.0 - SQL Injection via channelId, email, or username Parameter
CVSS 9.8
Details
Vulnerabilities 19,889
Exploit Likelihood High