CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,911 vulnerabilities with CWE-89
CVE-2017-8198
HIGH
FusionSphere V100R006C00SPC102(NFV) - Authenticated SQL Injection
CVSS 7.2
CVE-2017-16896
CRITICAL
Tiny Tiny RSS 17.4 - SQL Injection via Forgot Password Login Parameter
CVSS 9.8
CVE-2017-1000129
HIGH
Serendipity 2.0.3 - Info Disclosure
CVSS 7.5
CVE-2017-16851
CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16850
CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16849
CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16848
CRITICAL
Zoho ManageEngine Apps Mgr <13 - SQL Injection
CVSS 9.8
CVE-2017-16847
CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16846
CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-12302
MEDIUM
Cisco Unified Communications Manager - SQL Injection
CVSS 4.3
CVE-2017-16561
CRITICAL
Ingenious School Management System 2.3.0 - SQL Injection
CVSS 9.8
CVE-2017-16543
CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16542
HIGH
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 8.8
CVE-2017-11508
HIGH
SecurityCenter <5.5.3 - SQL Injection
CVSS 8.8
CVE-2017-16510
CRITICAL
WordPress < 4.8.3 - SQL Injection via Double Prepare Approach
CVSS 9.8
CVE-2017-12276
HIGH
Cisco Prime Collaboration Provisioning - SQL Injection
CVSS 8.1
CVE-2017-14356
CRITICAL
HP ArcSight ESM <6.9.1c-6.11.0 - SQL Injection
CVSS 9.8
CVE-2017-15993
CRITICAL
Zomato Clone Script - SQL Injection via Restaurant-Menu resid Parameter
CVSS 9.8
CVE-2017-15992
CRITICAL
Website Broker Script - SQL Injection via status_id Parameter
CVSS 9.8
CVE-2017-15991
CRITICAL
Vastal I-Tech Agent Zone - SQL Injection via searchCommercial.php or searchResidential.php Parameters
CVSS 9.8
CVE-2017-15989
CRITICAL
Online Exam Test Application - SQL Injection via Sort Parameter
CVSS 9.8
CVE-2017-15988
CRITICAL
nice_php_faq_script - SQL Injection via index.php nice_theme Parameter
CVSS 9.8
CVE-2017-15987
CRITICAL
fake_magazine_cover_script - SQL Injection via rate.php value parameter or content.php id parameter
CVSS 9.8
CVE-2017-15986
CRITICAL
CPA Lead Reward Script - SQL Injection via Username Parameter
CVSS 9.8
CVE-2017-15985
CRITICAL
Basic B2B Script - SQL Injection via product_view1.php pid or id Parameter
CVSS 9.8
Details
Vulnerabilities
19,911
Exploit Likelihood
High