CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,913 vulnerabilities with CWE-89
CVE-2016-1218 HIGH
Cybozu Garoon <4.2.2 - SQL Injection
CVSS 8.8
CVE-2016-6818 CRITICAL
SAP Business Intelligence Platform - SQL Injection
CVSS 9.8
CVE-2016-2566 CRITICAL
Samsung Galaxy S6 Firmware - SQL Injection in SecEmailSync
CVSS 9.8
CVE-2016-2555 CRITICAL
ATutor 2.2.1 - SQL Injection via searchFriends Function
CVSS 9.8
CVE-2016-1914 HIGH
BlackBerry Enterprise Server 12 - SQL Injection
CVSS 8.8
CVE-2016-4893 HIGH
Setucocms - SQL Injection
CVSS 8.8
CVE-2016-4337 CRITICAL
Ktools.net Photostore <4.7.5 - SQL Injection
CVSS 9.8
CVE-2016-4468 HIGH
Pivotal Cloud Foundry < 238 and UAA < 2.7.4.4/3.3.0.2/3.4.1 - Authenticated SQL Injection
CVSS 8.8
CVE-2016-8027 CRITICAL
Intel Security McAfee ePO <5.3.2 & <5.1.3 - SQL Injection
CVSS 10.0
CVE-2016-8025 MEDIUM
Intel Security VSEL <2.0.3 - Info Disclosure
CVSS 6.2
CVE-2016-9728 HIGH
IBM QRadar SIEM 7.2 - SQL Injection
CVSS 7.5
CVE-2016-9087 CRITICAL
Exponent CMS <2.3.9 - SQL Injection
CVSS 9.8
CVE-2016-9020 CRITICAL
Exponent CMS <2.3.9 - SQL Injection
CVSS 9.8
CVE-2016-9019 CRITICAL
Exponent CMS <2.3.9 - SQL Injection
CVSS 9.8
CVE-2016-7789 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via apikey Parameter
CVSS 9.8
CVE-2016-7788 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2016-7784 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via Section Parameter
CVSS 9.8
CVE-2016-7783 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via Title Parameter
CVSS 9.8
CVE-2016-7782 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via src Parameter
CVSS 9.8
CVE-2016-7781 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via Blog Author Parameter
CVSS 9.8
CVE-2016-7780 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via Version Parameter
CVSS 9.8
CVE-2016-10204 CRITICAL
ZoneMinder < 1.30.0 - SQL Injection via Log Query Limit Parameter
CVSS 9.8
CVE-2016-9994 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0 and 10.0.0 - SQL Injection
CVSS 7.1
CVE-2016-9993 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0 and 10.0.0 - SQL Injection
CVSS 7.1
CVE-2016-9992 HIGH
IBM Kenexa LCMS Premier on Cloud 9.0 and 10.0.0 - SQL Injection
CVSS 7.1
Details
Vulnerabilities 19,913
Exploit Likelihood High