CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,889 vulnerabilities with CWE-89
CVE-2018-7579 HIGH
YzmCMS 3.6 - SQL Injection via catids Array Parameter
CVSS 7.2
CVE-2018-7477 CRITICAL
School Management Script 3.0.4 - SQL Injection via Parent Login Username and Password Fields
CVSS 9.8
CVE-2018-7463 CRITICAL
ASANHAMAYESH CMS 3.4.6 - SQL Injection via Files Component ID Parameter
CVSS 9.8
CVE-2018-6883 MEDIUM
Piwigo < 2.9.3 - Authenticated SQL Injection via tags Array Parameter
CVSS 4.9
CVE-2018-6859 CRITICAL
Schools Alert Management Script 2.0.2 - SQL Injection via Login Parameter
CVSS 9.8
CVE-2018-7319 CRITICAL
OS Property Real Estate 3.12.7 - SQL Injection via Cooling System, Heating System, or Laundry Parameter
CVSS 9.8
CVE-2018-7318 CRITICAL
belitsoft checklist SQL Injection via title_search, tag_search, name_search, description_search, or filter_order
CVSS 9.8
CVE-2018-7315 CRITICAL
Ek Rishta 2.9 - SQL Injection via Gender, Age, Religion, Mother Tongue, Caste, or Country Parameter
CVSS 9.8
CVE-2018-7314 CRITICAL
PrayerCenter 3.0.2 - SQL Injection via Session ID Parameter
CVSS 9.8
CVE-2018-7312 CRITICAL
alexandria_book_library 3.1.2 - SQL Injection via Letter Parameter
CVSS 9.8
CVE-2018-1414 HIGH
IBM Maximo Asset Management <7.6 - SQL Injection
CVSS 8.8
CVE-2018-7313 CRITICAL
CW Tags 2.0.6 - SQL Injection via Searchtext Array Parameter
CVSS 9.8
CVE-2018-6024 CRITICAL
Joomla! Project Log 1.5.3 - SQL Injection
CVSS 9.8
CVE-2018-7180 CRITICAL
Saxum Astro 4.0.14 - SQL Injection via publicid Parameter
CVSS 9.8
CVE-2018-7179 CRITICAL
SquadManagement 1.0.3 - SQL Injection via id Parameter
CVSS 9.8
CVE-2018-7178 CRITICAL
Saxum Picker 3.2.10 - SQL Injection via Publicid Parameter
CVSS 9.8
CVE-2018-7177 CRITICAL
Saxum Numerology 3.0.4 - SQL Injection via publicid Parameter
CVSS 9.8
CVE-2018-6585 CRITICAL
JTicketing 2.0.16 - SQL Injection via filter_creator or filter_events_cat Parameter
CVSS 9.8
CVE-2018-6584 CRITICAL
DT Register 3.2.7 - SQL Injection via Task Parameter
CVSS 9.8
CVE-2018-6583 CRITICAL
Timetable Responsive Schedule 1.5 - SQL Injection via view=event&alias= Request
CVSS 9.8
CVE-2018-6396 CRITICAL
Google Map Landkarten <= 4.2.3 - SQL Injection via cid/id/map Parameters
CVSS 9.8
CVE-2018-6394 CRITICAL
InviteX 3.0.5 - SQL Injection via invite_type Parameter
CVSS 9.8
CVE-2018-6373 CRITICAL
fastball 2.5 - SQL Injection via Season Parameter
CVSS 9.8
CVE-2018-6372 CRITICAL
JB Bus 2.3 - SQL Injection via order_number Parameter
CVSS 9.8
CVE-2018-6370 CRITICAL
NeoRecruit 4.1 - SQL Injection via PATH_INFO or .html File Name
CVSS 9.8
Details
Vulnerabilities 19,889
Exploit Likelihood High