CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2015-1310
SAP Adaptive Server Enterprise - SQL Injection
CVE-2015-1055
Photo Gallery <1.2.7 - SQL Injection
CVE-2015-0919
Sefrengo < 1.6.0 - Authenticated SQL Injection via idcat or idclient Parameter
CVE-2014-125123 CRITICAL
Kloxo < 6.1.12 - Unauthenticated SQL Injection via Login-Name Parameter
CVE-2014-125115 CRITICAL
Pandora FMS <5.0 SP2 - SQL Injection
CVE-2014-125101 MEDIUM
Portfolio Gallery Plugin < 1.1.9 - SQL Injection
CVSS 6.3
CVE-2014-125099 MEDIUM
I Recommend This Plugin <= 3.7.2 - SQL Injection in dot-irecommendthis.php
CVSS 6.3
CVE-2014-125091 MEDIUM
codepeople polls_cp 1.0.1 - SQL Injection via lu Argument
CVSS 4.7
CVE-2014-125086 MEDIUM
Gimmie Plugin < 1.3.0 - SQL Injection via trigger_login.php userid Parameter
CVSS 5.5
CVE-2014-125085 MEDIUM
Gimmie < 1.3.0 - SQL Injection via t/postusername Parameter
CVSS 5.5
CVE-2014-125084 MEDIUM
Gimmie Plugin < 1.3.0 - SQL Injection via referrername Argument
CVSS 5.5
CVE-2014-125083 MEDIUM
Anant Labs google-enterprise-connector-dctm <= 3.2.3 - SQL Injection via Username/Domain Argument
CVSS 5.5
CVE-2014-125082 MEDIUM
redports < 2014-01-14 - SQL Injection in redports-trac/redports/model.py
CVSS 5.5
CVE-2014-125081 MEDIUM
debutsav < 2014-10-05 - SQL Injection
CVSS 5.5
CVE-2014-125079 MEDIUM
pontifex.http < 0.1.0 - SQL Injection in lib/Http.coffee
CVSS 5.5
CVE-2014-125077 MEDIUM
searx_stats < 2014-12-19 - SQL Injection in cron.php
CVSS 5.5
CVE-2014-125076 MEDIUM
criminals - SQL Injection via gambleMoney Argument in ingame/roulette.php
CVSS 5.5
CVE-2014-125075 MEDIUM
gmail-servlet - SQL Injection in search Function
CVSS 5.5
CVE-2014-125074 MEDIUM
Nayshlok Voyager < 2014-11-17 - SQL Injection in DatabaseAccess.java
CVSS 5.5
CVE-2014-125073 MEDIUM
voteapp < 2014-12-30 - SQL Injection via create_poll/do_poll/show_poll/show_refresh Functions
CVSS 5.5
CVE-2014-125072 MEDIUM
klattr < 2014-09-04 - SQL Injection
CVSS 5.5
CVE-2014-125067 MEDIUM
curiosity_project curiosity < 12-07-2014 - SQL Injection via sol Argument
CVSS 5.5
CVE-2014-125029 MEDIUM
PaginationServiceProvider < 1.0.0 - SQL Injection via sort/id Argument
CVSS 5.5
CVE-2014-125065 MEDIUM
bottle-auth < 2014-12-15 - SQL Injection
CVSS 5.5
CVE-2014-125063 MEDIUM
Bid < 2014-12-03 - SQL Injection
CVSS 5.5
Details
Vulnerabilities 19,915
Exploit Likelihood High