CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2015-2824
Simple Ads Manager < 2.7.97 - SQL Injection via Multiple Parameters
CVE-2015-0684
Cisco Unified Communications Domain Manager 8.1(4) - Authenticated SQL Injection in Image Management
CVE-2015-2679
genixcms < 0.0.1 - SQL Injection via Page or Username Parameter
CVE-2015-2564
ProjectSend r561 - Authenticated SQL Injection via ID Parameter
CVE-2015-2563
Vastal I-Tech phpVID 0.9.9 and 1.2.3 - SQL Injection via groups.php order_by Parameter
CVE-2015-2562
Web-Dorado ECommerce WD for Joomla! search_category_id SQL Injection Scanner
CVE-2015-2314
WPML < 3.1.8 - SQL Injection via HTTP Referer Header
CVE-2015-2292
WordPress SEO by Yoast < 1.5.7, 1.6.x < 1.6.4, 1.7.x < 1.7.4 - SQL Injection via order_by or order
CVE-2015-2237
Betster 1.0.4 - SQL Injection via id or username Parameter
CVE-2015-0524
EMC Secure Remote Services Virtual Edition 3.02 and 3.03 - SQL Injection
CVE-2015-1875
Elastix < 2.5.0 - SQL Injection via transactionID Parameter
CVE-2015-2183
ZeusCart 4 - Authenticated SQL Injection via Admin Backend Parameters
CVE-2015-2242
Webshop hun 1.062S - SQL Injection via termid or nyelv_id Parameter
CVE-2015-0894
All In One WP Security & Firewall < 3.8.7 - SQL Injection
CVE-2015-2216
Photocrati < 4.07 - SQL Injection via prod_id Parameter
CVE-2015-2199
WonderPlugin Audio Player < 2.0 - Authenticated SQL Injection via item[id] Parameter
CVE-2015-2196
Spider Event Calendar 1.4.9 - SQL Injection via cat_id Parameter
CVE-2015-2102
ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) - SQL Injection via Item Parameter
CVE-2015-2090
WordPress Survey and Poll 1.1.7 - SQL Injection via survey_id Parameter
CVE-2015-2070
eTouch SamePage Enterprise Edition 4.4.0.0.239 - SQL Injection via catId Parameter
CVE-2015-2066
DLGuard 4.5 - SQL Injection via Index.php c Parameter
CVE-2015-2065
Apptha WordPress Video Gallery < 2.7 - SQL Injection via vid Parameter
CVE-2015-1605
Dell ScriptLogic Asset Manager <9.5 - SQL Injection
CVE-2015-2035
Piwigo < 2.7.3 - Authenticated SQL Injection via User Parameter in History Page
CVE-2015-1517
Piwigo < 2.7.3 - Authenticated SQL Injection via Filter Level Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High