CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,914 vulnerabilities with CWE-89
CVE-2015-7999
HIGH
Citrix Command Center <5.1.36.7, <5.2.44.11 - SQL Injection
CVSS 8.1
CVE-2015-8604
HIGH
Cacti < 0.8.8f - Authenticated SQL Injection via graphs_new.php cg_g Parameter
CVSS 8.8
CVE-2015-8153
HIGH
Symantec Endpoint Protection Manager <12.1 - SQL Injection
CVSS 8.8
CVE-2015-7448
MEDIUM
IBM Maximo Asset Management <7.6.0.3 IFIX001 - SQL Injection
CVSS 5.4
CVE-2015-6319
CRITICAL
Cisco RV220W Router Firmware - SQL Injection via HTTP Request Header
CVSS 9.8
CVE-2015-3947
HIGH
Advantech WebAccess <8.1 - SQL Injection
CVSS 8.1
CVE-2015-8769
HIGH
Joomla! 3.x < 3.4.7 - SQL Injection
CVSS 7.3
CVE-2015-8261
CRITICAL
Ipswitch WhatsUp Gold <16.4 - SQL Injection
CVSS 9.8
CVE-2015-6433
MEDIUM
Cisco Unified Communications Manager 11.0(0.98000.225) - Authenticated SQL Injection via Crafted URL
CVSS 6.5
CVE-2015-5023
MEDIUM
IBM Curam Social Program Management 6.1 - Authenticated SQL Injection
CVSS 5.4
CVE-2015-5049
MEDIUM
IBM OpenPages GRC Platform 7.0-7.0.0.4 and 7.1-7.1.0.1 - Authenticated SQL Injection
CVSS 5.4
CVE-2015-7784
MEDIUM
BOKUBLOCK <1.1, <2.1 - SQL Injection
CVSS 4.3
CVE-2015-7791
MEDIUM
Collne Welcart <1.5.3 - SQL Injection
CVSS 6.3
CVE-2015-6537
CRITICAL
Epiphany Cardio Server 3.3 - SQL Injection via Login Page URL Parameter
CVSS 9.8
CVE-2015-6004
MEDIUM
IPSwitch WhatsUp Gold <16.4 - SQL Injection
CVSS 6.5
CVE-2015-8369
Cacti < 0.8.8f - SQL Injection via rra_id Parameter
CVE-2015-8377
Cacti < 0.8.8f - Authenticated SQL Injection via graphs_new.php selected_graphs_array Parameter
CVE-2015-2213
WordPress < 4.2.3 - SQL Injection via Trashed Comment Handling
CVE-2015-1989
IBM Security QRadar Incident Forensics 7.2.x - Authenticated SQL Injection
CVE-2015-5308
wp-championship plugin 5.8 - SQL Injection
CVE-2015-6350
Cisco Prime Service Catalog 11.0 - Authenticated SQL Injection
CVE-2015-6345
Cisco Secure Access Control Server 5.7(0.15) - Authenticated SQL Injection via Crafted URL
CVE-2015-7858
Joomla! 3.2-3.4.3 - SQL Injection
CVE-2015-7857
Joomla! 3.2-3.4.4 - SQL Injection via list[select] Parameter
CVE-2015-7297
Joomla! 3.2-3.4.3 - SQL Injection
Details
Vulnerabilities
19,914
Exploit Likelihood
High