CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2014-1924
CRITICAL
Koha <3.8.23, <3.10.13, <3.12.10, <3.14.3 - SQL Injection
CVSS 9.8
CVE-2014-4984
CRITICAL
Déjà Vu Crescendo Sales CRM - SQL Injection
CVSS 9.8
CVE-2014-8673
CRITICAL
SOPPlanning <1.33 - SQL Injection
CVSS 9.8
CVE-2014-5140
HIGH
Loaded Commerce 7 - Authenticated SQL Injection via Address Book Fields
CVSS 8.8
CVE-2014-7257
CRITICAL
DBD::PgPP < 0.05 - SQL Injection
CVSS 9.8
CVE-2014-10387
CRITICAL
WP Support Plus Responsive Ticket System < 4.2 - SQL Injection
CVSS 9.8
CVE-2014-10379
CRITICAL
duplicate-post < 2.6 - SQL Injection
CVSS 9.8
CVE-2014-10376
CRITICAL
i_recommend_this < 3.7.3 - SQL Injection
CVSS 9.8
CVE-2014-6045
HIGH
phpmyfaq < 2.8.13 - Authenticated SQL Injection via Restore Function
CVSS 7.2
CVE-2014-4959
CRITICAL
Android - SQL Injection via SQLiteDatabase delete Method
CVSS 9.8
CVE-2014-4928
HIGH
Invision Power Board <3.4.6 - SQL Injection
CVSS 8.8
CVE-2014-2652
CRITICAL
OpenScape Deployment Service <6.x,7.x.R1.11.3 - SQL Injection
CVSS 9.8
CVE-2014-5071
CRITICAL
Symmetricom s350i 2.70.15 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2014-4914
CRITICAL
Zend Framework <1.12.7 - SQL Injection
CVSS 9.8
CVE-2014-2023
CRITICAL
Tapatalk plugin <4.9.0, 5.x-5.2.1 - SQL Injection
CVSS 9.8
CVE-2014-8621
CRITICAL
Store Locator 2.3-3.11 - SQL Injection via sl_custom_field Parameter
CVSS 9.8
CVE-2014-9558
CRITICAL
SmartCMS 2 - SQL Injection
CVSS 9.8
CVE-2014-9229
Symantec SEP <12.1.6 - SQL Injection
CVE-2014-9145
Fiyo CMS 2.0.1.8 - SQL Injection via Multiple Parameters
CVE-2014-9566
Solarwinds Orion Platform <11.5 - SQL Injection
CVE-2014-7864
ManageEngine OpManager 8-11.5 - SQL Injection via FailOverHelperServlet Parameters
CVE-2014-9573
MantisBT <1.2.19, <1.3.0-beta.2 - SQL Injection
CVE-2014-7289
Symantec SCSP <5.2.9, SDCS:SA <6.0 MP1 - SQL Injection
CVE-2014-7814
Red Hat CloudForms 3.1 Management Engine 5.3 - Authenticated SQL Injection via REST API SQL Filter
CVE-2014-9560
SoftBB 0.1.3 - SQL Injection via redir_last_post_list.php post Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High