CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,913 vulnerabilities with CWE-89
CVE-2016-6611 HIGH
phpMyAdmin <4.6.4, <4.4.15.8, <4.0.10.17 - SQL Injection
CVSS 8.1
CVE-2016-2873 HIGH
IBM QRadar Security Information and Event Manager < 7.1.0 - Authenticated SQL Injection
CVSS 8.8
CVE-2016-2950 MEDIUM
IBM BigFix Remote Control < 9.1.3 - Authenticated SQL Injection
CVSS 6.5
CVE-2016-9481 CRITICAL
Exponent CMS 2.4.0 - SQL Injection via content_id Parameter
CVSS 9.8
CVE-2016-9287 CRITICAL
Exponent CMS 2.4.0 patch1 - SQL Injection
CVSS 9.8
CVE-2016-8908 HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8907 HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8906 HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8905 HIGH
dotcms < 3.3 - Authenticated SQL Injection via JSONTags Servlet Sort Parameter
CVSS 8.8
CVE-2016-8904 HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8903 HIGH
dotcms < 3.3 - Authenticated SQL Injection via Orderby Parameter
CVSS 8.8
CVE-2016-8902 CRITICAL
dotcms < 3.3 - Unauthenticated SQL Injection via CategoriesServlet Sort Parameter
CVSS 9.8
CVE-2016-9288 CRITICAL
Exponent CMS <2.4.0 - SQL Injection
CVSS 9.8
CVE-2016-9283 HIGH
Exponent CMS <2.4.0 - SQL Injection
CVSS 7.5
CVE-2016-9282 HIGH
Exponent CMS <2.4.0 - SQL Injection
CVSS 7.5
CVE-2016-9272 CRITICAL
Exponent CMS <2.4.0 - SQL Injection
CVSS 9.1
CVE-2016-9242 HIGH
Exponent CMS 2.4.0 - Authenticated SQL Injection via Content Type or Subtype Parameter
CVSS 8.8
CVE-2016-9184 HIGH
Exponent CMS 2.4.0 - SQL Injection and Information Disclosure via Table Name Manipulation
CVSS 7.5
CVE-2016-6453 HIGH
Cisco ISE <1.3 - Privilege Escalation
CVSS 7.3
CVE-2016-9135 HIGH
Exponent CMS 2.3.9 - SQL Injection in Help Controller Version Parameter
CVSS 7.5
CVE-2016-9134 HIGH
Exponent CMS 2.3.9 - SQL Injection in expPaginator.php Order Parameter
CVSS 7.5
CVE-2016-7453 CRITICAL
Exponent CMS < 2.3.9 - SQL Injection via Pixidou Image Editor
CVSS 9.8
CVE-2016-8582 CRITICAL
AlienVault OSSIM & USM <5.3.2 - SQL Injection
CVSS 9.8
CVE-2016-7919 HIGH
Moodle 3.1.2 - Exposure of Sensitive Information via SQL Injection in Installation Process
CVSS 7.5
CVE-2016-6443 HIGH
Cisco Prime Infrastructure - SQL Injection
CVSS 8.8
Details
Vulnerabilities 19,913
Exploit Likelihood High