CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2015-4129
Subrion CMS < 3.3.2 - Authenticated SQL Injection via Salt Cookie
CVE-2015-4233
Cisco Unified MeetingPlace 8.6(1.2) - Authenticated SQL Injection
CVE-2015-5148
LivelyCart 1.2.0 - SQL Injection via Search Query Parameter
CVE-2015-5078
LimeSurvey 2.06+ - Authenticated SQL Injection via Closedate Parameter
CVE-2015-4222
Cisco Unified Communications Manager IM and Presence Service 9.1(1) - Authenticated SQL Injection
CVE-2015-4208
Cisco WebEx Meeting Center - Exposure of Sensitive Information via URL Parameter
CVE-2015-4713
ApPHP Hotel Site 3.x.x - SQL Injection via PID Parameter
CVE-2015-4678
Persian Car CMS 1.0 - SQL Injection via cat_id Parameter
CVE-2015-4676
TickFa 1.x - Authenticated SQL Injection via tid Parameter
CVE-2015-4658
Milw0rm Clone Script 1.0 - SQL Injection via usr or pwd Parameter
CVE-2015-4654
Joomla! EQ Event Calendar - SQL Injection via id Parameter
CVE-2015-4628
LimeSurvey < 2.06+ - Authenticated SQL Injection via sid Parameter
CVE-2015-4454
Cacti < 0.8.8d - SQL Injection via graph_template_id Parameter
CVE-2015-4342
Cacti < 0.8.8d - SQL Injection via CDEF ID
CVE-2015-2803
Akronymmanager < 0.5.0 - Authenticated SQL Injection via id Parameter
CVE-2015-4188
Cisco Prime Collaboration 10.5(1) - SQL Injection via Crafted URL
CVE-2015-4613
Developer Log < 2.11.3 - SQL Injection
CVE-2015-4612
FAQ - Frequently Asked Questions < 1.2.0 - Authenticated SQL Injection
CVE-2015-4611
Smoelenboek < 1.0.8 - Authenticated SQL Injection
CVE-2015-4610
Store Locator < 3.3.0 - Authenticated SQL Injection
CVE-2015-4609
wt_directory < 1.4.1 - Authenticated SQL Injection
CVE-2015-4118
ISPConfig < 3.0.5.4 - Authenticated SQL Injection via server Parameter
CVE-2015-4348
Spider Contacts for Drupal - Authenticated SQL Injection
CVE-2015-3993
Actian Matrix 5.1.x-5.1.2.4 and 5.2.x-5.2.0.1 - Authenticated SQL Injection
CVE-2015-2956
Igreks MilkyStep <0.94 - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High