CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,911 vulnerabilities with CWE-89
CVE-2017-6754
MEDIUM
Cisco Smart Net Total Care Software Collector Appliance 3.11 - Authenticated Blind SQL Injection via Crafted URLs
CVSS 6.5
CVE-2017-12585
HIGH
SLiMS 8 Akasia through 8.3.1 - Authenticated SQL Injection via admin/AJAX_lookup_handler.php
CVSS 8.8
CVE-2017-10816
CRITICAL
MaLion 5.0.0-5.2.1 - SQL Injection via Relay Service Server
CVSS 9.8
CVE-2017-11388
HIGH
Trend Micro Control Manager 6.0 - SQL Injection and Remote Code Execution via RestfulServiceUtility.NET.dll
CVSS 8.8
CVE-2017-11386
CRITICAL
Trend Micro Control Manager 6.0 - Remote Code Execution via SQL Injection in cmdHandlerNewReportScheduler.dll
CVSS 9.8
CVE-2017-11385
CRITICAL
Trend Micro Control Manager 6.0 - Remote Code Execution via SQL Injection in cmdHandlerStatusMonitor.dll
CVSS 9.8
CVE-2017-11384
CRITICAL
Trend Micro Control Manager 6.0 - SQLi & RCE via Opcode 0x3b21 in mdHandlerLicenseManager.dll
CVSS 9.8
CVE-2017-11383
CRITICAL
Trend Micro Control Manager 6.0 - SQL Injection and Remote Code Execution via Opcode 0x1b07
CVSS 9.8
CVE-2017-11494
CRITICAL
SOL.Connect ISET-mpp meter <1.2.4.2 - SQL Injection
CVSS 9.8
CVE-2017-12199
CRITICAL
Etoile Ultimate Product Catalog <4.2.11 - SQL Injection
CVSS 9.8
CVE-2017-11736
HIGH
BigTree CMS 4.2.18 - Authenticated SQL Injection via Tags Array Parameter
CVSS 8.8
CVE-2017-11184
CRITICAL
GLPI < 9.1.4 - SQL Injection via start Parameter
CVSS 9.8
CVE-2017-11678
HIGH
Hashtopus 1.5g - Authenticated SQL Injection via Admin.php Format Parameter
CVSS 8.8
CVE-2017-11631
CRITICAL
Fiyo CMS 2.0.7 - SQL Injection via id Parameter
CVSS 9.8
CVE-2017-11324
CRITICAL
Tilde CMS 1.0.1 - SQL Injection via id Parameter in action.input.php
CVSS 9.8
CVE-2017-11584
CRITICAL
dayrui FineCms 5.0.9 - SQL Injection
CVSS 9.8
CVE-2017-11583
CRITICAL
dayrui FineCms 5.0.9 - SQL Injection
CVSS 9.8
CVE-2017-11582
CRITICAL
dayrui FineCms 5.0.9 - SQL Injection
CVSS 9.8
CVE-2017-3221
CRITICAL
Inmarsat AmosConnect 8 - Blind SQL Injection via Login Form
CVSS 9.8
CVE-2017-11475
HIGH
GLPI < 9.1.5.0 - SQL Injection via Condition Rule Field
CVSS 8.8
CVE-2017-11474
CRITICAL
GLPI < 9.1.5.0 - SQL Injection via $crit Variable in Computer Software Version Class
CVSS 9.8
CVE-2017-11471
CRITICAL
IDERA Uptime Monitor 7.8 - SQL Injection
CVSS 9.8
CVE-2017-11470
CRITICAL
IDERA Uptime Monitor 7.8 - SQL Injection
CVSS 9.8
CVE-2017-11445
CRITICAL
Subrion CMS < 4.1.4 - SQL Injection via POST Array
CVSS 9.8
CVE-2017-11444
CRITICAL
Subrion CMS < 4.1.4 - SQL Injection via Search GET Parameter
CVSS 9.8
Details
Vulnerabilities
19,911
Exploit Likelihood
High