CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-125062 MEDIUM
bitstorm < 2014-12-14 - SQL Injection via announce.php Event Parameter
CVSS 5.5
CVE-2014-125061 MEDIUM
filebroker < 2014-02-18 - SQL Injection in select_transfer_status_desc Function
CVSS 5.5
CVE-2014-125058 MEDIUM
address_book_project address_book < 2014-11-22 - SQL Injection in search_first_name Function
CVSS 5.5
CVE-2014-125053 MEDIUM
Piwigo-Guest-Book < 1.3.1 - SQL Injection via Navigation Bar start Argument
CVSS 5.5
CVE-2014-125052 MEDIUM
sparql-identifiers < 2014-05-19 - SQL Injection in RegistryDao.java
CVSS 5.5
CVE-2014-125051 MEDIUM
yii2-jqgrid-widget < 1.0.8 - SQL Injection in JqGridAction.php addSearchOptionsRecursively
CVSS 5.5
CVE-2014-125050 MEDIUM
voter-js < 2014-11-30 - SQL Injection in main.js
CVSS 5.5
CVE-2014-125049 MEDIUM
blogile < 2014-12-02 - SQL Injection via getNav Function Query Parameter
CVSS 5.5
CVE-2014-125047 MEDIUM
school-store < 11-23-2014 - SQL Injection
CVSS 5.5
CVE-2014-125046 MEDIUM
cub-scout-tracker < 9-14-2014 - SQL Injection in databaseAccessFunctions.js
CVSS 5.5
CVE-2014-125045 MEDIUM
meol1 < 2014-11-24 - SQL Injection via GetAnimal Function
CVSS 5.5
CVE-2014-125041 MEDIUM
progetto-complementi < 2014-06-25 - SQL Injection
CVSS 5.5
CVE-2014-125040 MEDIUM
DevNewsAggregator < 2014-11-30 - SQL Injection via getByName Function
CVSS 5.5
CVE-2014-125038 MEDIUM
IS_Projecto2 < 2014-11-12 - SQL Injection via NewsBean.java Date Argument
CVSS 5.5
CVE-2014-125037 MEDIUM
License to Kill < 2014-05-01 - SQL Injection in models/injury.rb
CVSS 5.5
CVE-2014-125032 MEDIUM
go-with-me < 2014-12-08 - SQL Injection in module/frontend/add.php
CVSS 5.5
CVE-2014-8941 CRITICAL
Lexiglot <2014-11-20 - SQL Injection
CVSS 9.8
CVE-2014-1634 CRITICAL
Advanced Newsletter <2.3.5 - SQL Injection
CVSS 9.8
CVE-2014-9613 CRITICAL
Netsweeper <2.6.29.10 - SQL Injection
CVSS 9.8
CVE-2014-9612 CRITICAL
Netsweeper < 3.1.10, 4.0.x < 4.0.9, 4.1.x < 4.1.2 - SQL Injection via Server Parameter
CVSS 9.8
CVE-2014-8089 CRITICAL
Zend Framework < 1.12.9, 2.2.x < 2.2.8, 2.3.x < 2.3.3 - SQL Injection via Null Byte
CVSS 9.8
CVE-2014-3868 HIGH
ZeusCart 4.x - SQL Injection
CVSS 8.8
CVE-2014-3119 HIGH
web2project < 3.1 - Authenticated SQL Injection via Search String or Update Key Parameter
CVSS 8.8
CVE-2014-3719 CRITICAL
Ex Libris ALEPH 500 18.1 and 20 - SQL Injection via find lib or sid Parameter
CVSS 9.8
CVE-2014-1925 CRITICAL
Koha < 3.08.23 - Authenticated SQL Injection in MARC Framework Import/Export
CVSS 9.8
Details
Vulnerabilities 19,915
Exploit Likelihood High