CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-3978
TomatoCart <1.1.8.6.1 - SQL Injection
CVE-2014-2081
Innovative vtls-Virtua <2014.1.1 - SQL Injection
CVE-2014-8306
C97net Cart Engine < 3.0 - SQL Injection via item_id Parameter
CVE-2014-3704
Drupal 7.0-7.31 - SQL Injection via Array Key in Database API
CVE-2014-8295
Bacula-Web 5.2.10 - SQL Injection via Joblogs JobID Parameter
CVE-2014-8294
Voice Of Web AllMyGuests 0.4.1 - SQL Injection via Cookie or Credentials
CVE-2014-2022
vBulletin < 4.2.2 - Authenticated SQL Injection via XMLRPC API conceptid Argument
CVE-2014-8766
Allomani Weblinks 1.0 - SQL Injection
CVE-2014-7201
TYPO3 dmmjobcontrol <2.14.0 - SQL Injection
CVE-2014-4313
Epicor Procurement <7.4 SP2 - SQL Injection
CVE-2014-4873
BMC Track-It! 11.3.0.355 - SQL Injection
CVE-2014-3382
Cisco ASA Software 7.2-9.1 - Denial of Service via SQL*Net Inspection Engine
CVE-2014-7981
Joomla! 3.1.x-3.2.x - SQL Injection
CVE-2014-5308
TestLink 1.9.11 - Authenticated SQL Injection via Name or ID Parameter
CVE-2014-5503
CyberoamOS < 10.6.1 - SQL Injection via Guest Login Portal add_guest_user Opcode
CVE-2014-5389
Content Audit < 1.6.1 - SQL Injection via Audited Content Types Option
CVE-2014-6295
WEC Map < 3.0.3 - SQL Injection
CVE-2014-6293
TYPO3 ke_stats <1.1.2 - SQL Injection
CVE-2014-6242
All In One WP Security & Firewall <3.8.3 - SQL Injection
CVE-2014-7153
Huge-IT Image Gallery <1.0.1 - SQL Injection
CVE-2014-4424
Apple OS X Server <3.2.1 - SQL Injection
CVE-2014-4824
IBM Security QRadar SIEM <7.2.3 - SQL Injection
CVE-2014-2376
Ecava IntegraXor SCADA Server <4.1.4360 - SQL Injection
CVE-2014-5440
Mpexsolutions Mx-smartimer < 13.18.5.11 - SQL Injection
CVE-2014-2008
mpay24 < 1.6 - SQL Injection via TID Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High