CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-9457
PMB < 4.1.3 - Authenticated SQL Injection via id Parameter
CVE-2014-9455
CTS Projects & Software ClassAd 3.0 - SQL Injection
CVE-2014-9450
Zabbix <1.8.22, <2.0.14, <2.2.8 - SQL Injection
CVE-2014-9445
Installatron GQ File Manager 0.2.5 - SQL Injection
CVE-2014-9442
Cart66 Lite < 1.5.4 - Authenticated SQL Injection via Promotion Product Search
CVE-2014-9440
phpMyRecipes 1.2.2 - SQL Injection via Category Parameter
CVE-2014-9435
Absolut Engine 1.73 - SQL Injection
CVE-2014-9254
MiniBB < 3.1 - SQL Injection via Unsubscribe Code Parameter
CVE-2014-8810
WP Symposium <14.11 - SQL Injection
CVE-2014-9115
Piwigo <2.5.5, <2.6.x before 2.6.4, <2.7.x before 2.7.2 - SQL Injec...
CVE-2014-9258
GLPI < 0.85 - Authenticated SQL Injection via Dropdown Condition Parameter
CVE-2014-6080
IBM Security Access Manager SQL Injection (Mobile 8.x < 8.0.1, Web 7.x < 7.0.0 FP10, 8.x < 8.0.1)
CVE-2014-8248
CA Release Automation < 4.7.1 - Authenticated SQL Injection
CVE-2014-9057
Movable Type <5.18, <5.2.11, <6.0.6 - SQL Injection
CVE-2014-8340
phpTrafficA < 2.2.1 - SQL Injection via User-Agent HTTP Header
CVE-2014-8507
Android < 4.4.4 - SQL Injection via WAPPushManager PDU Fields
CVE-2014-9348
RobotStats 1.0 - SQL Injection via Robot Parameter
CVE-2014-9347
phpMyRecipes 1.2.2 - SQL Injection via dosearch.php words_exact Parameter
CVE-2014-9345
Guruperl.net AWP PRO <6.6 - SQL Injection
CVE-2014-9305
Cart66 Lite < 1.5.1.17 - Authenticated SQL Injection via id Parameter
CVE-2014-5462
OpenEMR < 4.1.2 - Authenticated SQL Injection via Multiple Parameters
CVE-2014-9215
PBBoard < 3.0.1 - SQL Injection via Email Parameter in Register Page
CVE-2014-3997
ManageEngine Password Manager Pro 5-7 build 7003 - SQL Injection via MetadataServlet sv Parameter
CVE-2014-3996
ManageEngine <9-0.90043 - SQL Injection
CVE-2014-7868
ManageEngine OpManager 11.3-11.4, IT360 10.3-10.4, Social IT Plus 11.0 SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High