CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,914 vulnerabilities with CWE-89
CVE-2015-10018
MEDIUM
DBRisinajumi d2files <1.0.0 - SQL Injection
CVSS 5.5
CVE-2015-10017
MEDIUM
HPI-Information-Systems ProLOD - SQL Injection
CVSS 5.5
CVE-2015-10016
MEDIUM
jeff-kelley opensim-utils - SQL Injection
CVSS 5.5
CVE-2015-10015
MEDIUM
glidernet ogn-live < 2015-02-07 - SQL Injection
CVSS 5.5
CVE-2015-10014
MEDIUM
uke_project uke < 2015-11-17 - SQL Injection in lib/uke/finder.rb
CVSS 5.5
CVE-2015-10008
MEDIUM
weipdcrm < 2015-04-01 - SQL Injection
CVSS 6.3
CVE-2015-7342
HIGH
JNews < 8.5.0 - SQL Injection via Upload Thumbnail or Search Fields
CVSS 7.2
CVE-2015-7340
HIGH
JEvents < 3.4.0 - SQL Injection via evid Parameter
CVSS 7.2
CVE-2015-7338
HIGH
AcyMailing < 4.9.5 - SQL Injection via exportgeolocorder Parameter
CVSS 7.2
CVE-2015-7567
CRITICAL
Yeager CMS 1.2.1 - SQL Injection via Password Reset Token Parameter
CVSS 9.8
CVE-2015-5617
CRITICAL
Enorth Webpublisher CMS - SQL Injection
CVSS 9.8
CVE-2015-3423
HIGH
NetCracker Resource Management System <8.2 - SQL Injection
CVSS 8.8
CVE-2015-2062
HIGH
Huge-IT Slider < 2.7.0 - Authenticated SQL Injection via removeslide Parameter
CVSS 7.2
CVE-2015-0244
CRITICAL
PostgreSQL SQL Injection via Crafted Binary Data in Protocol Message
CVSS 9.8
CVE-2015-5591
HIGH
zenphoto < 1.4.9 - Authenticated SQL Injection
CVSS 7.2
CVE-2015-3424
HIGH
Accentis Content Resource Management System < 10-2015 - SQL Injection via SIDX Parameter
CVSS 8.8
CVE-2015-0270
CRITICAL
Zend Framework < 2.2.10 - SQL Injection in PostgreSQL Zend\Db Adapter
CVSS 9.8
CVE-2015-9496
HIGH
freshmail-newsletter < 1.6 - SQL Injection via FM_form Shortcode
CVSS 8.8
CVE-2015-9467
CRITICAL
Broken Link Manager < 0.5.0 - SQL Injection via url Parameter
CVSS 9.8
CVE-2015-9466
CRITICAL
wti_like_post < 1.4.3 - SQL Injection via HTTP Client IP Headers
CVSS 9.8
CVE-2015-9465
HIGH
yet_another_stars_rating < 0.9.1 - SQL Injection via set_id Parameter
CVSS 8.8
CVE-2015-9462
HIGH
awesome_filterable_portfolio < 1.9 - SQL Injection via cat_id Parameter
CVSS 7.2
CVE-2015-9461
HIGH
awesome_filterable_portfolio < 1.9 - SQL Injection via item_id Parameter
CVSS 7.2
CVE-2015-9460
HIGH
Pinpoint Booking System < 2.1 - SQL Injection via Language Parameter
CVSS 8.8
CVE-2015-9458
HIGH
searchterms-tagging-2 < 1.535 - SQL Injection via Popular Terms Count Parameter
CVSS 7.2
Details
Vulnerabilities
19,914
Exploit Likelihood
High