CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,914 vulnerabilities with CWE-89
CVE-2015-5668
Techno Project Japan Enisys Gw <1.4.1 - SQL Injection
CVE-2015-7903
Infinite Automation Mango Automation <2.6.0 - SQL Injection
CVE-2015-6486
Allen-Bradley MicroLogix 1100 < 15.000 and 1400 < 15.003 - Authenticated SQL Injection
CVE-2015-7299
K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 - SQL Injection via Runtime/AjaxCall.ashx xml Parameter
CVE-2015-7876
Drupal 7 Driver for SQL Server and SQL Azure < 7.x-1.4 - SQL Injection via db_like Function
CVE-2015-7682
Pie Register <2.0.19 - SQL Injection
CVE-2015-7727
SAP HANA DB <1.00.73.00.389160 - SQL Injection
CVE-2015-7725
SAP HANA DB <1.00.091.00.1418659308 - SQL Injection
CVE-2015-6331
Cisco Prime Collaboration Assurance 10.5(1) - Authenticated SQL Injection
CVE-2015-6329
Cisco Prime Collaboration Provisioning 10.6 and 11.0 - Authenticated SQL Injection
CVE-2015-5659
Network Applied Communication Laboratory Pref Shimane CMS <2.0.1 - ...
CVE-2015-5648
phpRechnung < 1.6.4 - Authenticated SQL Injection
CVE-2015-5642
ICZ MATCHA INVOICE <2.5.7 - SQL Injection
CVE-2015-5641
baserCMS < 3.0.7 - Authenticated SQL Injection
CVE-2015-4967
IBM Maximo Asset Management 7.1-7.1.1.13, 7.5.0 < 7.5.0.8 IFIX004, 7.6.0 < 7.6.0.1 IFIX002 - Authenticated SQL Injection
CVE-2015-7319
Appointment Booking Calendar < 1.1.7 - SQL Injection via Username Update
CVE-2015-5703
Open-Xchange OX Guard <2.0.0-rev8 - SQL Injection
CVE-2015-7387
ManageEngine EventLog Analyzer < 10.6 - SQL Injection via event/runQuery.do Query Parameter
CVE-2015-7382
refbase < 0.9.6 - SQL Injection via defaultCharacterSet Parameter
CVE-2015-6009
Web Reference Database <0.9.6 - SQL Injection
CVE-2015-6548
Symantec Web Gateway < 5.2.2 - Authenticated SQL Injection
CVE-2015-6299
Cisco Unity Connection 9.1(1.2) - Authenticated SQL Injection via Web Interface
CVE-2015-7239
SAP NetWeaver J2EE Engine 7.40 - SQL Injection via BP_FIND_JOBS_WITH_PROGRAM Function Module
CVE-2015-7235
CP Reservation Calendar < 1.1.6 - SQL Injection via dex_reservations.php Parameters
CVE-2015-6962
Farol - SQL Injection via Email Parameter
Details
Vulnerabilities 19,914
Exploit Likelihood High