CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,913 vulnerabilities with CWE-89
CVE-2016-4522 CRITICAL
Rockwell Automation FactoryTalk EnergyMetrix < 2.10.00 - SQL Injection
CVSS 9.8
CVE-2016-5653 MEDIUM
Misys FusionCapital Opics Plus - SQL Injection
CVSS 6.5
CVE-2016-1446 HIGH
Cisco WebEx Meetings Server 2.6 - SQL Injection
CVSS 8.8
CVE-2016-4507 MEDIUM
Bosch BLADEcontrol-WebVIS <= 3.0.2 - Authenticated SQL Injection
CVSS 6.4
CVE-2016-5703 CRITICAL
phpMyAdmin <4.4.15.7, <4.6.3 - SQL Injection
CVSS 9.8
CVE-2016-0233 HIGH
IBM Marketing Platform <9.1.2.2 - SQL Injection
CVSS 8.8
CVE-2016-0224 CRITICAL
IBM Marketing Platform <9.1.2.2 - SQL Injection
CVSS 9.8
CVE-2016-1437 MEDIUM
Cisco Prime Collaboration Deployment <11.5.1 - SQL Injection
CVSS 6.5
CVE-2016-2174 HIGH
Apache Ranger < 0.5.3 - Authenticated SQL Injection via eventTime Parameter
CVSS 7.2
CVE-2016-3072 HIGH
Katello - Authenticated SQL Injection via Scoped Search Parameters
CVSS 8.8
CVE-2016-1393 HIGH
Cisco Cloud Network Automation Provisioner 1.0 and 1.1 - Authenticated SQL Injection via Crafted URL
CVSS 7.1
CVE-2016-4350 CRITICAL
SolarWinds SRM Profiler <6.2.3 - SQL Injection
CVSS 9.8
CVE-2016-2351 CRITICAL
Accellion File Transfer Appliance < 9_11_210 - SQL Injection via client_id Parameter
CVSS 9.8
CVE-2016-4351 CRITICAL
Trend Micro Email Encryption Gateway <5.5 - SQL Injection
CVSS 9.8
CVE-2016-2301 MEDIUM
Ecava IntegraXor < 4.2.4502 - Authenticated SQL Injection
CVSS 6.3
CVE-2016-2299 HIGH
Ecava IntegraXor < 4.2.4502 - SQL Injection
CVSS 7.3
CVE-2016-4040 HIGH
dotcms < 3.3.1 - Authenticated SQL Injection via Workflow Screen Orderby Parameter
CVSS 7.2
CVE-2016-3172 HIGH
Cacti < 0.8.8g - Authenticated SQL Injection via tree.php parent_id Parameter
CVSS 8.8
CVE-2016-3675 HIGH
Huawei Policy Center <V100R003C10SPC020 - SQL Injection
CVSS 8.1
CVE-2016-3659 HIGH
Cacti < 0.8.8g - Authenticated SQL Injection via Host Group Data Parameter
CVSS 8.8
CVE-2016-0710 HIGH
Apache Jetspeed Arbitrary File Upload
CVSS 8.8
CVE-2016-1154 CRITICAL
Cuore EC-CUBE <1.3.5 - SQL Injection
CVSS 9.1
CVE-2016-2386 CRITICAL KEV
SAP NetWeaver Application Server Java 7.40 - SQL Injection
CVSS 9.8
CVE-2016-1308 MEDIUM
Cisco Unified Communications Manager <10.5(2.13900.9) - SQL Injection
CVSS 6.5
CVE-2015-20121 HIGH
RealtyScript 4.0.2 SQL Injection via u_id and agent Parameters
CVSS 8.2
Details
Vulnerabilities 19,913
Exploit Likelihood High