CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2015-4109
Usersultra < 1.5.15 - SQL Injection
CVE-2015-2999
SysAid Help Desk <15.2 - SQL Injection
CVE-2015-4160
SAP ASE Database Platform - SQL Injection
CVE-2015-4159
SAP HANA Web-based Development Workbench - SQL Injection
CVE-2015-4137
Milw0rm Clone Script 1.0 - SQL Injection via Related.php Program Parameter
CVE-2015-1392
Aruba Networks ClearPass Policy Manager <6.4.5 - SQL Injection
CVE-2015-4066
GigPress < 2.3.8 - Authenticated SQL Injection via show_artist_id or show_venue_id Parameter
CVE-2015-4064
Landing Pages < 1.8.4 - Authenticated SQL Injection via post Parameter
CVE-2015-4062
NewStatPress < 0.9.8 - Authenticated SQL Injection via where1 Parameter
CVE-2015-1013
OSIsoft PI AF <2.6-2.7 & PI SQL for AF 2.1.2.19 - Auth Bypass
CVE-2015-1008
Emerson AMS Device Manager <13 - Privilege Escalation
CVE-2015-0540
EMC Document Sciences xPression 4.2 before P44 and 4.5 SP1 before P03 - Authenticated SQL Injection
CVE-2015-0161
IBM Security SiteProtector System 3.0-3.0.0.6, 3.1-3.1.0.3, 3.1.1-3.1.1.1 - Authenticated SQL Injection
CVE-2015-0916
Cacti < 0.8.6f - Authenticated SQL Injection via local_graph_id Parameter
CVE-2015-4018
FeedWordPress < 2015.0514 - Authenticated SQL Injection via link_ids[] Parameter
CVE-2015-3325
WP Symposium < 15.2 - SQL Injection via Forum Show Parameter
CVE-2015-3427
Quassel < 0.12.2 - SQL Injection via Backslash in Message
CVE-2015-3980
SAP Customer Relationship Management - SQL Injection in Business Rules Framework
CVE-2015-2843
GoAutoDial GoAdmin CE - SQL Injection via User Credentials or PATH_INFO
CVE-2015-0715
Cisco Unity Connection - Authenticated SQL Injection
CVE-2015-1397
Magento CE/EE 1.9.1.0-1.14.1.0 - SQL Injection
CVE-2015-1889
IBM InfoSphere BigInsights 3.0-3.0.0.2 SQL Injection via Big SQL
CVE-2015-3346
Drupal WikiWiki <6.x-1.2 - SQL Injection
CVE-2015-3345
PHPlist Integration Module <6.x-1.7 - SQL Injection
CVE-2015-0699
Cisco Unified Communications Manager 10.5(1.98991.13) - SQL Injection in IVR Component
Details
Vulnerabilities 19,915
Exploit Likelihood High