CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,911 vulnerabilities with CWE-89
CVE-2017-12227 MEDIUM
Cisco Emergency Responder - SQL Injection
CVSS 5.4
CVE-2017-9834 CRITICAL
WatuPRO < 5.5.1 - SQL Injection via watupro_questions Parameter
CVSS 9.8
CVE-2017-14145 CRITICAL
HelpDEZk 1.1.1 - SQL Injection via admin/login/getWarningInfo/id PATH_INFO
CVSS 9.8
CVE-2017-14076 CRITICAL
NexusPHP <1.5.beta5.20120707 - SQL Injection
CVSS 9.8
CVE-2017-14069 CRITICAL
NexusPHP <1.5.beta5.20120707 - SQL Injection
CVSS 9.8
CVE-2017-12710 HIGH
Advantech WebAccess < 8.2 - SQL Injection
CVSS 7.5
CVE-2017-10842 CRITICAL
baserCMS < 3.0.14 and 4.0.5 - SQL Injection
CVSS 9.8
CVE-2017-10839 HIGH
SEO Panel < 3.11.0 - Authenticated SQL Injection
CVSS 8.8
CVE-2017-13669 CRITICAL
NexusPHP 1.5.beta5.20120707 - SQL Injection via setanswered Parameter
CVSS 9.8
CVE-2017-12679 CRITICAL
NexusPHP 1.5.beta5.20120707 - SQL Injection via delcheater Parameter
CVSS 9.8
CVE-2017-13137 CRITICAL
FormCraft Basic 1.0.5 - SQL Injection via id Parameter
CVSS 9.8
CVE-2017-12981 CRITICAL
NexusPHP 1.5.beta5.20120707 - SQL Injection via Forum Manage Sort Parameter
CVSS 9.8
CVE-2017-12977 HIGH
Photo Gallery by WD < 1.3.50 - Authenticated SQL Injection via tag_id Parameter
CVSS 7.2
CVE-2017-12949 HIGH
Podlove Podcast Publisher <= 2.5.3 - SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2017-12947 HIGH
easy_modal < 2.0.17 - Authenticated SQL Injection via Untrash Action
CVSS 7.2
CVE-2017-12946 HIGH
easy_modal < 2.0.17 - Authenticated SQL Injection via id/ids/modal Parameter
CVSS 7.2
CVE-2017-12776 CRITICAL
NexusPHP 1.5 - SQL Injection via reports.php delreport Parameter
CVSS 9.8
CVE-2017-12910 CRITICAL
NexusPHP 1.5 - SQL Injection via Massmail or Parameter
CVSS 9.8
CVE-2017-12909 CRITICAL
NexusPHP 1.5 - SQL Injection via modtask.php userid Parameter
CVSS 9.8
CVE-2017-12908 CRITICAL
NexusPHP 1.5 - SQL Injection via takeconfirm.php conusr Parameter
CVSS 9.8
CVE-2017-1174 HIGH
IBM Sterling B2B Integrator Standard Edition 5.2 - SQL Injection
CVSS 8.8
CVE-2017-12774 CRITICAL
finecms 1.9.5 - SQL Injection via ContentController
CVSS 9.8
CVE-2017-12650 CRITICAL
Loginizer < 1.3.5 - SQL Injection via X-Forwarded-For HTTP Header
CVSS 9.8
CVE-2017-12567 CRITICAL
Quest KACE Asset Management Appliance 6.4.120822-7.2 - SQL Injection
CVSS 9.8
CVE-2017-6757 HIGH
Cisco Unified Communications Manager <11.5 - Blind SQL Injection
CVSS 8.8
Details
Vulnerabilities 19,911
Exploit Likelihood High