CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2014-7867
ZOHO ManageEngine OpManager 11.3-11.4, IT360 10.3-10.4, Social IT Plus 11.0 - SQL Injection via probeName Parameter
CVE-2014-9242
WebsiteBaker 2.8.3 - SQL Injection via page_id Parameter
CVE-2014-9240
MyBB 1.8.x < 1.8.2 - SQL Injection via member.php question_id Parameter
CVE-2014-9239
Invision Power Board <3.4.7 - SQL Injection
CVE-2014-9237
Pricertif E-Commerce 3.0 - SQL Injection
CVE-2014-9235
Zoph < 0.9.1 - Authenticated SQL Injection via _action or location_id Parameter
CVE-2014-9220
OpenVAS Manager <4.0.6, <5.0.7 - SQL Injection
CVE-2014-9178
Smarty Pants Plugins SP Project & Document Manager <2.4.1 - SQL Inj...
CVE-2014-9175
wpDataTables <1.5.3 - SQL Injection
CVE-2014-9173
Google Doc Embedder <2.5.15 - SQL Injection
CVE-2014-8728
Subex ROC Fraud Mgmt <7.4 - SQL Injection
CVE-2014-9089
MantisBT <1.2.18 - SQL Injection
CVE-2014-9102
Kunena < 3.0.6 - Authenticated SQL Injection via Array Parameter Index
CVE-2014-9097
Apptha WordPress Video Gallery 2.5 - SQL Injection
CVE-2014-9096
Pligg CMS < 2.0.1 - SQL Injection via Recover.php ID or N Parameter
CVE-2014-9095
Raritan Power IQ <4.2.1 - SQL Injection
CVE-2014-8367
Aruba Networks ClearPass Policy Manager 6.2.x-6.3.x < 6.3.6 and 6.4.x < 6.4.2 - SQL Injection
CVE-2014-8682
Gogs 0.3.1-0.5.x - SQL Injection via Search API q Parameter
CVE-2014-8681
Gogs 0.3.1-0.5.6.x - SQL Injection via Label Parameter
CVE-2014-7871
Open-Xchange AppSuite < 7.4.2-rev36 and 7.6.x < 7.6.0-rev23 - Authenticated SQL Injection via jslob API
CVE-2014-7137
Dolibarr ERP/CRM <3.6.1 - SQL Injection
CVE-2014-9005
vldPersonals <2.7.1 - SQL Injection
CVE-2014-8999
XOOPS < 2.5.6 - Authenticated SQL Injection via selgroups Parameter
CVE-2014-8995
Maarch LetterBox 2.8 - SQL Injection
CVE-2014-8596
php-fusion 7.02.07 - Authenticated SQL Injection via submit_id or status Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High