CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,914 vulnerabilities with CWE-89
CVE-2015-5052 CRITICAL
Sefrengo < 1.6.5 - SQL Injection
CVSS 9.8
CVE-2015-4724 HIGH
Concrete CMS 5.7.3.1 - SQL Injection
CVSS 8.8
CVE-2015-4627 CRITICAL
Pragyan CMS 3.0 - SQL Injection
CVSS 9.8
CVE-2015-3314 HIGH
WordPress Tune Library <1.5.5 - SQL Injection
CVSS 8.1
CVE-2015-3313 CRITICAL
WordPress Community Events <1.4 - SQL Injection
CVSS 9.8
CVE-2015-8334 HIGH
Huawei VCN500 <V100R002C00SPC201 - SQL Injection
CVSS 8.8
CVE-2015-7517 CRITICAL
WordPress Double Opt-In <2.0.9 - SQL Injection
CVSS 9.8
CVE-2015-8355 HIGH
Bitrix Orion <2.1.3 - SQL Injection
CVSS 8.8
CVE-2015-3616 CRITICAL
Fortinet FortiManager <5.0.11, <5.2.2 - SQL Injection
CVSS 9.8
CVE-2015-0782 CRITICAL
Novell ZENworks Configuration Management - SQL Injection via ScheduleQuery Method
CVSS 9.8
CVE-2015-0780 CRITICAL
Novell ZENworks Configuration Management - SQL Injection
CVSS 9.8
CVE-2015-2798 CRITICAL
Contact Form Maker 1.0.1 - SQL Injection via id Parameter
CVSS 9.8
CVE-2015-9098 CRITICAL
Redgate SQL Monitor < 3.10 and 4.x < 4.2 - Unauthenticated SQL Injection
CVSS 9.8
CVE-2015-7346 CRITICAL
ZCMS 1.1 - SQL Injection
CVSS 9.8
CVE-2015-7569 HIGH
Yeager CMS 1.2.1 - SQL Injection via pagedir_orderby Parameter
CVSS 8.8
CVE-2015-7568 CRITICAL
Yeager CMS 1.2.1 - SQL Injection via Password Recovery UserEmail Parameter
CVSS 9.8
CVE-2015-8356 HIGH
Bitrix mcart.xls <6.5.2 - SQL Injection
CVSS 8.0
CVE-2015-7564 CRITICAL
TeamPass < 2.1.24 - SQL Injection via Item Query or View Log Parameters
CVSS 9.8
CVE-2015-6028 HIGH
Castle Rock Computing SNMPc <2015-12-17 - SQL Injection
CVSS 8.8
CVE-2015-8974 CRITICAL
MyBB Merge System < 1.8.6 and MyBB < 1.6.18 and 1.8.x < 1.8.6 - SQL Injection in Group Promotions Module
CVSS 10.0
CVE-2015-4592 HIGH
eClinicalWorks Population Health - Authenticated SQL Injection via portalUserService.jsp
CVSS 8.8
CVE-2015-1000011 CRITICAL
WordPress Dukapress <2.5.9 - SQL Injection
CVSS 9.8
CVE-2015-1000003 CRITICAL
filedownload v1.4 - Blind SQL Injection
CVSS 9.8
CVE-2015-8157 HIGH
Symantec Embedded Security - SQL Injection
CVSS 8.8
CVE-2015-7695 CRITICAL
Zend Framework <1.12.16 - SQL Injection
CVSS 9.8
Details
Vulnerabilities 19,914
Exploit Likelihood High