CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-8499
ManageEngine Password Manager Pro < 7.1 - Authenticated SQL Injection via SEARCH_ALL Parameter
CVE-2014-8498
ManageEngine Password Manager Pro < 7.1 - Authenticated SQL Injection via BulkEditSearchResult.cc SEARCH_ALL Parameter
CVE-2014-8554
MantisBT < 1.2.18 - SQL Injection via mc_project_get_attachments project_id Parameter
CVE-2014-4627 HIGH
EMC RSA Web Threat Detection <4.6.1.1 - SQL Injection
CVSS 8.8
CVE-2014-6030
ClassApps SelectSurvey.NET < 4.125.002 - SQL Injection via SurveyID Parameter
CVE-2014-8668
SAP Contract Accounting - SQL Injection
CVE-2014-8664
SAP Environment, Health, and Safety Management - SQL Injection
CVE-2014-8663
SAP NetWeaver Business Warehouse - SQL Injection
CVE-2014-8351
CookieViz < 1.0 - SQL Injection via Domain Parameter
CVE-2014-7959
BulletProof Security < .51.1 - Authenticated SQL Injection via tableprefix Parameter
CVE-2014-8588
SAP HANA - SQL Injection in metadata.xsjs
CVE-2014-8586
CP Multi View Event Calendar 1.01 - SQL Injection via calid Parameter
CVE-2014-8339
nuevolab nuevoplayer for ClipShare < 8.0 - SQL Injection via midroll.php ch Parameter
CVE-2014-7176
Enalean Tuleap <7.5.99.4 - SQL Injection
CVE-2014-5387
ExpressionEngine < 2.9.1 - Authenticated SQL Injection via column_filter, category[], or tbl_sort Parameters
CVE-2014-3366
Cisco Unified Communications Manager - Authenticated SQL Injection
CVE-2014-3446
BSS Continuity CMS 4.2.22640.0 - SQL Injection via nodeid Parameter
CVE-2014-8506
Etiko CMS - SQL Injection via page_id or article_id Parameter
CVE-2014-5520
xrms_crm - SQL Injection via user_id Parameter
CVE-2014-3828
Centreon 2.5.1 and Centreon Enterprise Server 2.2 - SQL Injection via Multiple Parameters
CVE-2014-2531
InterWorx Web Control Panel <5.0.14 - SQL Injection
CVE-2014-8375
gb_gallery_slideshow 1.5 - Authenticated SQL Injection via selected_group Parameter
CVE-2014-8366
openSIS 4.5-5.3 - SQL Injection via Username and Password Parameters
CVE-2014-8363
WordPress Spreadsheet 0.62 - SQL Injection via ss_id Parameter
CVE-2014-5275
Pro Chat Rooms Text Chat Rooms 8.2.0 - Authenticated SQL Injection via Password, Email, or ID Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High