CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,914 vulnerabilities with CWE-89
CVE-2015-6829
WP Limit Login Attempts < 2.0.0 - SQL Injection via X-Forwarded-For or Client-IP Header
CVE-2015-6943
Serendipity < 2.0.2 - Authenticated SQL Injection via serendipity[id] Parameter
CVE-2015-6915
ResourceSpace < 7.3.7009 - SQL Injection via User Cookie
CVE-2015-6911
Synology Video Station < 1.5-0757 - SQL Injection via id Parameter
CVE-2015-6910
Synology Video Station < 1.5-0754 - SQL Injection via id Parameter
CVE-2015-6811
CyberoamOS <= 10.6.2 MR-1 - SQL Injection via login.xml Username Parameter
CVE-2015-6659
Drupal 7.x < 7.39 - SQL Injection via SQL Comment Filtering
CVE-2015-6522
WP Symposium < 15.7 - SQL Injection via Size Parameter
CVE-2015-6519
Arab Portal 3 - SQL Injection via showemail Parameter
CVE-2015-5504
Novalnet Payment Module - SQL Injection
CVE-2015-4426
pimcore < build 3473 - SQL Injection via Admin Asset Grid-Proxy Filter Parameter
CVE-2015-6516
sysPass < 1.0.9 - Authenticated SQL Injection via Search Parameter
CVE-2015-6513
j2store < 3.1.6 - SQL Injection via sortby or manufacturer_ids[] Parameter
CVE-2015-6512
FreiChat 9.6 - SQL Injection via Time Parameter
CVE-2015-5599
Powerplay Gallery <3.3 - SQL Injection
CVE-2015-4634
Cacti < 0.8.8d - SQL Injection via graphs.php local_graph_id Parameter
CVE-2015-1491
Symantec SEPM <12.1-RU6-MP1 - SQL Injection
CVE-2015-2972
Sysphonic Thetis <2.3.0 - SQL Injection
CVE-2015-1560
Centreon < 2.5.4 - SQL Injection via sid Parameter
CVE-2015-4614
easy2map < 1.2.4 - SQL Injection via mapName Parameter
CVE-2015-5459
ManageEngine PMP <8.1 - SQL Injection
CVE-2015-5452
Watchguard XCS <10.0 - SQL Injection
CVE-2015-2866
Grandstream GXV3611_HD Firmware < 1.0.3.6 - SQL Injection via TELNET Username
CVE-2015-2849
ANTlabs InnGate - SQL Injection via ppli Parameter
CVE-2015-4129
Subrion CMS < 3.3.2 - Authenticated SQL Injection via Salt Cookie
Details
Vulnerabilities 19,914
Exploit Likelihood High