CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2014-6241
TYPO3 wt_directory <1.4.1 - SQL Injection
CVE-2014-6239
Address visualization with Google Maps < 0.3.6 - SQL Injection
CVE-2014-6233
TYPO3 Flat Manager <2.7.10 - SQL Injection
CVE-2014-5521
xrms_crm - Authenticated Remote Code Execution via Username Parameter
CVE-2014-5399
Schneider Electric Wonderware Information Server Portal 4.0 SP1-5.5 - SQL Injection
CVE-2014-3041
IBM Emptoris Contract Management 9.5.x-10.0.2.x - Authenticated SQL Injection
CVE-2014-5458
php-sqrl - SQL Injection via Message Parameter
CVE-2014-5262
Cacti < 0.8.8b - SQL Injection via Graph Settings
CVE-2014-5097
ArticleFR < 3.0.4 - SQL Injection via rate.php id Parameter
CVE-2014-4197
Bank Soft Systems BSS BS-Client <3.17.9 - SQL Injection
CVE-2014-5383
AlienVault OSSIM < 4.7.0 - Authenticated SQL Injection
CVE-2014-5159
AlienVault OSSIM < 4.6.0 - SQL Injection via ws_data Parameter
CVE-2014-3906
OSK Advance-Flow <4.41 - SQL Injection
CVE-2014-0966
IBM InfoSphere Master Data Management - Authenticated SQL Injection in GDS Component
CVE-2014-3904
tenfourzero Shutter 0.1.4 - SQL Injection
CVE-2014-5249
Biblio Autocomplete 6.x-1.x < 6.x-1.1 and 7.x-1.x < 7.x-1.5 - SQL Injection
CVE-2014-3339
Cisco Unified Communications Manager and Unified Presence Server - Authenticated SQL Injection
CVE-2014-5201
Gallery Objects 0.4 - SQL Injection via viewid Parameter
CVE-2014-5200
FB Gorilla - SQL Injection via game_play.php id Parameter
CVE-2014-3336
Cisco Unity Connection 9.1(2) and earlier - Authenticated SQL Injection
CVE-2014-5192
Sphider 1.3.6 - SQL Injection via Admin Filter Parameter
CVE-2014-5189
Lead Octopus - SQL Injection via id Parameter
CVE-2014-3773
TeamPass < 2.1.20 - SQL Injection via Multiple Parameters
CVE-2014-5186
All Video Gallery 1.2 - Authenticated SQL Injection via id Parameter
CVE-2014-5185
quartz_plugin 1.01.1 - Authenticated SQL Injection via Quote Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High