CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,911 vulnerabilities with CWE-89
CVE-2017-6754 MEDIUM
Cisco Smart Net Total Care Software Collector Appliance 3.11 - Authenticated Blind SQL Injection via Crafted URLs
CVSS 6.5
CVE-2017-12585 HIGH
SLiMS 8 Akasia through 8.3.1 - Authenticated SQL Injection via admin/AJAX_lookup_handler.php
CVSS 8.8
CVE-2017-10816 CRITICAL
MaLion 5.0.0-5.2.1 - SQL Injection via Relay Service Server
CVSS 9.8
CVE-2017-11388 HIGH
Trend Micro Control Manager 6.0 - SQL Injection and Remote Code Execution via RestfulServiceUtility.NET.dll
CVSS 8.8
CVE-2017-11386 CRITICAL
Trend Micro Control Manager 6.0 - Remote Code Execution via SQL Injection in cmdHandlerNewReportScheduler.dll
CVSS 9.8
CVE-2017-11385 CRITICAL
Trend Micro Control Manager 6.0 - Remote Code Execution via SQL Injection in cmdHandlerStatusMonitor.dll
CVSS 9.8
CVE-2017-11384 CRITICAL
Trend Micro Control Manager 6.0 - SQLi & RCE via Opcode 0x3b21 in mdHandlerLicenseManager.dll
CVSS 9.8
CVE-2017-11383 CRITICAL
Trend Micro Control Manager 6.0 - SQL Injection and Remote Code Execution via Opcode 0x1b07
CVSS 9.8
CVE-2017-11494 CRITICAL
SOL.Connect ISET-mpp meter <1.2.4.2 - SQL Injection
CVSS 9.8
CVE-2017-12199 CRITICAL
Etoile Ultimate Product Catalog <4.2.11 - SQL Injection
CVSS 9.8
CVE-2017-11736 HIGH
BigTree CMS 4.2.18 - Authenticated SQL Injection via Tags Array Parameter
CVSS 8.8
CVE-2017-11184 CRITICAL
GLPI < 9.1.4 - SQL Injection via start Parameter
CVSS 9.8
CVE-2017-11678 HIGH
Hashtopus 1.5g - Authenticated SQL Injection via Admin.php Format Parameter
CVSS 8.8
CVE-2017-11631 CRITICAL
Fiyo CMS 2.0.7 - SQL Injection via id Parameter
CVSS 9.8
CVE-2017-11324 CRITICAL
Tilde CMS 1.0.1 - SQL Injection via id Parameter in action.input.php
CVSS 9.8
CVE-2017-11584 CRITICAL
dayrui FineCms 5.0.9 - SQL Injection
CVSS 9.8
CVE-2017-11583 CRITICAL
dayrui FineCms 5.0.9 - SQL Injection
CVSS 9.8
CVE-2017-11582 CRITICAL
dayrui FineCms 5.0.9 - SQL Injection
CVSS 9.8
CVE-2017-3221 CRITICAL
Inmarsat AmosConnect 8 - Blind SQL Injection via Login Form
CVSS 9.8
CVE-2017-11475 HIGH
GLPI < 9.1.5.0 - SQL Injection via Condition Rule Field
CVSS 8.8
CVE-2017-11474 CRITICAL
GLPI < 9.1.5.0 - SQL Injection via $crit Variable in Computer Software Version Class
CVSS 9.8
CVE-2017-11471 CRITICAL
IDERA Uptime Monitor 7.8 - SQL Injection
CVSS 9.8
CVE-2017-11470 CRITICAL
IDERA Uptime Monitor 7.8 - SQL Injection
CVSS 9.8
CVE-2017-11445 CRITICAL
Subrion CMS < 4.1.4 - SQL Injection via POST Array
CVSS 9.8
CVE-2017-11444 CRITICAL
Subrion CMS < 4.1.4 - SQL Injection via Search GET Parameter
CVSS 9.8
Details
Vulnerabilities 19,911
Exploit Likelihood High