CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2015-1310
SAP Adaptive Server Enterprise - SQL Injection
CVE-2015-1055
Photo Gallery <1.2.7 - SQL Injection
CVE-2015-0919
Sefrengo < 1.6.0 - Authenticated SQL Injection via idcat or idclient Parameter
CVE-2014-125123
CRITICAL
Kloxo < 6.1.12 - Unauthenticated SQL Injection via Login-Name Parameter
CVE-2014-125115
CRITICAL
Pandora FMS <5.0 SP2 - SQL Injection
CVE-2014-125101
MEDIUM
Portfolio Gallery Plugin < 1.1.9 - SQL Injection
CVSS 6.3
CVE-2014-125099
MEDIUM
I Recommend This Plugin <= 3.7.2 - SQL Injection in dot-irecommendthis.php
CVSS 6.3
CVE-2014-125091
MEDIUM
codepeople polls_cp 1.0.1 - SQL Injection via lu Argument
CVSS 4.7
CVE-2014-125086
MEDIUM
Gimmie Plugin < 1.3.0 - SQL Injection via trigger_login.php userid Parameter
CVSS 5.5
CVE-2014-125085
MEDIUM
Gimmie < 1.3.0 - SQL Injection via t/postusername Parameter
CVSS 5.5
CVE-2014-125084
MEDIUM
Gimmie Plugin < 1.3.0 - SQL Injection via referrername Argument
CVSS 5.5
CVE-2014-125083
MEDIUM
Anant Labs google-enterprise-connector-dctm <= 3.2.3 - SQL Injection via Username/Domain Argument
CVSS 5.5
CVE-2014-125082
MEDIUM
redports < 2014-01-14 - SQL Injection in redports-trac/redports/model.py
CVSS 5.5
CVE-2014-125081
MEDIUM
debutsav < 2014-10-05 - SQL Injection
CVSS 5.5
CVE-2014-125079
MEDIUM
pontifex.http < 0.1.0 - SQL Injection in lib/Http.coffee
CVSS 5.5
CVE-2014-125077
MEDIUM
searx_stats < 2014-12-19 - SQL Injection in cron.php
CVSS 5.5
CVE-2014-125076
MEDIUM
criminals - SQL Injection via gambleMoney Argument in ingame/roulette.php
CVSS 5.5
CVE-2014-125075
MEDIUM
gmail-servlet - SQL Injection in search Function
CVSS 5.5
CVE-2014-125074
MEDIUM
Nayshlok Voyager < 2014-11-17 - SQL Injection in DatabaseAccess.java
CVSS 5.5
CVE-2014-125073
MEDIUM
voteapp < 2014-12-30 - SQL Injection via create_poll/do_poll/show_poll/show_refresh Functions
CVSS 5.5
CVE-2014-125072
MEDIUM
klattr < 2014-09-04 - SQL Injection
CVSS 5.5
CVE-2014-125067
MEDIUM
curiosity_project curiosity < 12-07-2014 - SQL Injection via sol Argument
CVSS 5.5
CVE-2014-125029
MEDIUM
PaginationServiceProvider < 1.0.0 - SQL Injection via sort/id Argument
CVSS 5.5
CVE-2014-125065
MEDIUM
bottle-auth < 2014-12-15 - SQL Injection
CVSS 5.5
CVE-2014-125063
MEDIUM
Bid < 2014-12-03 - SQL Injection
CVSS 5.5
Details
Vulnerabilities
19,915
Exploit Likelihood
High