CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-1924 CRITICAL
Koha <3.8.23, <3.10.13, <3.12.10, <3.14.3 - SQL Injection
CVSS 9.8
CVE-2014-4984 CRITICAL
Déjà Vu Crescendo Sales CRM - SQL Injection
CVSS 9.8
CVE-2014-8673 CRITICAL
SOPPlanning <1.33 - SQL Injection
CVSS 9.8
CVE-2014-5140 HIGH
Loaded Commerce 7 - Authenticated SQL Injection via Address Book Fields
CVSS 8.8
CVE-2014-7257 CRITICAL
DBD::PgPP < 0.05 - SQL Injection
CVSS 9.8
CVE-2014-10387 CRITICAL
WP Support Plus Responsive Ticket System < 4.2 - SQL Injection
CVSS 9.8
CVE-2014-10379 CRITICAL
duplicate-post < 2.6 - SQL Injection
CVSS 9.8
CVE-2014-10376 CRITICAL
i_recommend_this < 3.7.3 - SQL Injection
CVSS 9.8
CVE-2014-6045 HIGH
phpmyfaq < 2.8.13 - Authenticated SQL Injection via Restore Function
CVSS 7.2
CVE-2014-4959 CRITICAL
Android - SQL Injection via SQLiteDatabase delete Method
CVSS 9.8
CVE-2014-4928 HIGH
Invision Power Board <3.4.6 - SQL Injection
CVSS 8.8
CVE-2014-2652 CRITICAL
OpenScape Deployment Service <6.x,7.x.R1.11.3 - SQL Injection
CVSS 9.8
CVE-2014-5071 CRITICAL
Symmetricom s350i 2.70.15 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2014-4914 CRITICAL
Zend Framework <1.12.7 - SQL Injection
CVSS 9.8
CVE-2014-2023 CRITICAL
Tapatalk plugin <4.9.0, 5.x-5.2.1 - SQL Injection
CVSS 9.8
CVE-2014-8621 CRITICAL
Store Locator 2.3-3.11 - SQL Injection via sl_custom_field Parameter
CVSS 9.8
CVE-2014-9558 CRITICAL
SmartCMS 2 - SQL Injection
CVSS 9.8
CVE-2014-9229
Symantec SEP <12.1.6 - SQL Injection
CVE-2014-9145
Fiyo CMS 2.0.1.8 - SQL Injection via Multiple Parameters
CVE-2014-9566
Solarwinds Orion Platform <11.5 - SQL Injection
CVE-2014-7864
ManageEngine OpManager 8-11.5 - SQL Injection via FailOverHelperServlet Parameters
CVE-2014-9573
MantisBT <1.2.19, <1.3.0-beta.2 - SQL Injection
CVE-2014-7289
Symantec SCSP <5.2.9, SDCS:SA <6.0 MP1 - SQL Injection
CVE-2014-7814
Red Hat CloudForms 3.1 Management Engine 5.3 - Authenticated SQL Injection via REST API SQL Filter
CVE-2014-9560
SoftBB 0.1.3 - SQL Injection via redir_last_post_list.php post Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High