CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,911 vulnerabilities with CWE-89
CVE-2017-8198 HIGH
FusionSphere V100R006C00SPC102(NFV) - Authenticated SQL Injection
CVSS 7.2
CVE-2017-16896 CRITICAL
Tiny Tiny RSS 17.4 - SQL Injection via Forgot Password Login Parameter
CVSS 9.8
CVE-2017-1000129 HIGH
Serendipity 2.0.3 - Info Disclosure
CVSS 7.5
CVE-2017-16851 CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16850 CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16849 CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16848 CRITICAL
Zoho ManageEngine Apps Mgr <13 - SQL Injection
CVSS 9.8
CVE-2017-16847 CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16846 CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-12302 MEDIUM
Cisco Unified Communications Manager - SQL Injection
CVSS 4.3
CVE-2017-16561 CRITICAL
Ingenious School Management System 2.3.0 - SQL Injection
CVSS 9.8
CVE-2017-16543 CRITICAL
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 9.8
CVE-2017-16542 HIGH
Zoho ManageEngine Applications Manager <13 - SQL Injection
CVSS 8.8
CVE-2017-11508 HIGH
SecurityCenter <5.5.3 - SQL Injection
CVSS 8.8
CVE-2017-16510 CRITICAL
WordPress < 4.8.3 - SQL Injection via Double Prepare Approach
CVSS 9.8
CVE-2017-12276 HIGH
Cisco Prime Collaboration Provisioning - SQL Injection
CVSS 8.1
CVE-2017-14356 CRITICAL
HP ArcSight ESM <6.9.1c-6.11.0 - SQL Injection
CVSS 9.8
CVE-2017-15993 CRITICAL
Zomato Clone Script - SQL Injection via Restaurant-Menu resid Parameter
CVSS 9.8
CVE-2017-15992 CRITICAL
Website Broker Script - SQL Injection via status_id Parameter
CVSS 9.8
CVE-2017-15991 CRITICAL
Vastal I-Tech Agent Zone - SQL Injection via searchCommercial.php or searchResidential.php Parameters
CVSS 9.8
CVE-2017-15989 CRITICAL
Online Exam Test Application - SQL Injection via Sort Parameter
CVSS 9.8
CVE-2017-15988 CRITICAL
nice_php_faq_script - SQL Injection via index.php nice_theme Parameter
CVSS 9.8
CVE-2017-15987 CRITICAL
fake_magazine_cover_script - SQL Injection via rate.php value parameter or content.php id parameter
CVSS 9.8
CVE-2017-15986 CRITICAL
CPA Lead Reward Script - SQL Injection via Username Parameter
CVSS 9.8
CVE-2017-15985 CRITICAL
Basic B2B Script - SQL Injection via product_view1.php pid or id Parameter
CVSS 9.8
Details
Vulnerabilities 19,911
Exploit Likelihood High