CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,914 vulnerabilities with CWE-89
CVE-2015-7999 HIGH
Citrix Command Center <5.1.36.7, <5.2.44.11 - SQL Injection
CVSS 8.1
CVE-2015-8604 HIGH
Cacti < 0.8.8f - Authenticated SQL Injection via graphs_new.php cg_g Parameter
CVSS 8.8
CVE-2015-8153 HIGH
Symantec Endpoint Protection Manager <12.1 - SQL Injection
CVSS 8.8
CVE-2015-7448 MEDIUM
IBM Maximo Asset Management <7.6.0.3 IFIX001 - SQL Injection
CVSS 5.4
CVE-2015-6319 CRITICAL
Cisco RV220W Router Firmware - SQL Injection via HTTP Request Header
CVSS 9.8
CVE-2015-3947 HIGH
Advantech WebAccess <8.1 - SQL Injection
CVSS 8.1
CVE-2015-8769 HIGH
Joomla! 3.x < 3.4.7 - SQL Injection
CVSS 7.3
CVE-2015-8261 CRITICAL
Ipswitch WhatsUp Gold <16.4 - SQL Injection
CVSS 9.8
CVE-2015-6433 MEDIUM
Cisco Unified Communications Manager 11.0(0.98000.225) - Authenticated SQL Injection via Crafted URL
CVSS 6.5
CVE-2015-5023 MEDIUM
IBM Curam Social Program Management 6.1 - Authenticated SQL Injection
CVSS 5.4
CVE-2015-5049 MEDIUM
IBM OpenPages GRC Platform 7.0-7.0.0.4 and 7.1-7.1.0.1 - Authenticated SQL Injection
CVSS 5.4
CVE-2015-7784 MEDIUM
BOKUBLOCK <1.1, <2.1 - SQL Injection
CVSS 4.3
CVE-2015-7791 MEDIUM
Collne Welcart <1.5.3 - SQL Injection
CVSS 6.3
CVE-2015-6537 CRITICAL
Epiphany Cardio Server 3.3 - SQL Injection via Login Page URL Parameter
CVSS 9.8
CVE-2015-6004 MEDIUM
IPSwitch WhatsUp Gold <16.4 - SQL Injection
CVSS 6.5
CVE-2015-8369
Cacti < 0.8.8f - SQL Injection via rra_id Parameter
CVE-2015-8377
Cacti < 0.8.8f - Authenticated SQL Injection via graphs_new.php selected_graphs_array Parameter
CVE-2015-2213
WordPress < 4.2.3 - SQL Injection via Trashed Comment Handling
CVE-2015-1989
IBM Security QRadar Incident Forensics 7.2.x - Authenticated SQL Injection
CVE-2015-5308
wp-championship plugin 5.8 - SQL Injection
CVE-2015-6350
Cisco Prime Service Catalog 11.0 - Authenticated SQL Injection
CVE-2015-6345
Cisco Secure Access Control Server 5.7(0.15) - Authenticated SQL Injection via Crafted URL
CVE-2015-7858
Joomla! 3.2-3.4.3 - SQL Injection
CVE-2015-7857
Joomla! 3.2-3.4.4 - SQL Injection via list[select] Parameter
CVE-2015-7297
Joomla! 3.2-3.4.3 - SQL Injection
Details
Vulnerabilities 19,914
Exploit Likelihood High