CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,913 vulnerabilities with CWE-89
CVE-2017-8917 CRITICAL
Joomla! 3.7.x - SQL Injection
CVSS 9.8
CVE-2017-7952 HIGH
INFOR EAM V11.0 Build 201410 - SQL Injection via Search Filter Value Parameter
CVSS 8.8
CVE-2017-7886 CRITICAL
Dolibarr ERP/CRM 4.0.4 - SQL Injection via lang Parameter
CVSS 9.8
CVE-2017-5527 MEDIUM
Tibco Spotfire Analytics Platform For Aws < 7.8.0 - SQL Injection
CVSS 4.3
CVE-2017-8796 CRITICAL
Accellion File Transfer Appliance < 9_12_40 - SQL Injection via app_id Parameter
CVSS 9.8
CVE-2017-8789 CRITICAL
Accellion File Transfer Appliance < 9_12_40 - SQL Injection via report_error.php Year Parameter
CVSS 9.8
CVE-2017-6557 HIGH
ArrayOS < AG 9.4.0.135 - Authenticated SQL Injection via Portal Bookmark Function
CVSS 8.8
CVE-2017-8377 HIGH
GeniXCMS < 1.1.0 - SQL Injection via menuid Parameter
CVSS 8.8
CVE-2017-2120 HIGH
WBCE CMS <= 1.1.10 - Authenticated SQL Injection
CVSS 7.2
CVE-2017-7221 HIGH
OpenText Documentum Content Server - SQL Injection
CVSS 8.8
CVE-2017-3549 CRITICAL
Oracle E-Business Suite <12.2.6 - RCE
CVSS 9.1
CVE-2017-7991 CRITICAL
Exponent CMS < 2.4.1 - SQL Injection via Base64 Serialized API Key
CVSS 9.8
CVE-2017-7879 HIGH
flatcore-cms 1.4.6 - SQL Injection
CVSS 7.5
CVE-2017-7878 CRITICAL
flatcore-cms 1.4.6 - SQL Injection
CVSS 9.8
CVE-2017-7717 HIGH
SAP NetWeaver AS Java 7.4 - SQL Injection
CVSS 8.8
CVE-2017-7628 CRITICAL
Smart related articles 1.1 - SQL Injection via search_cats POST Parameter
CVSS 9.8
CVE-2017-7719 CRITICAL
Spider Event Calendar <1.5.52 - SQL Injection
CVSS 9.8
CVE-2017-6088 HIGH
EyesOfNetwork < 5.0 - Authenticated SQL Injection via bp_name, display, search, equipment, or type Parameter
CVSS 7.2
CVE-2017-7581 CRITICAL
TYPO3 News module <5.3.2 - SQL Injection
CVSS 9.8
CVE-2017-3886 MEDIUM
Cisco Unified Communications Manager - SQL Injection
CVSS 4.9
CVE-2017-7410 CRITICAL
WebsiteBaker <2.10.0 - SQL Injection
CVSS 9.8
CVE-2017-7290 HIGH
XOOPS < 2.5.8.1 - Authenticated SQL Injection via findusers.php url Parameter
CVSS 7.2
CVE-2017-6013 CRITICAL
Subrion CMS 4.0.5.10 - SQL Injection via Admin Database Query Parameter
CVSS 9.8
CVE-2017-2641 CRITICAL
Moodle 2.x-3.x - SQL Injection via User Preferences
CVSS 9.8
CVE-2017-6550 CRITICAL
Kinsey Infor-Lawson - SQL Injection via TABLE or QUERY Parameter
CVSS 9.8
Details
Vulnerabilities 19,913
Exploit Likelihood High