CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-5184
stripshow 2.5.2 - Authenticated SQL Injection via Story Parameter
CVE-2014-5183
Simple Retail Menus < 4.1 - Authenticated SQL Injection via targetmenu Parameter
CVE-2014-5182
yawpp 1.2 - Authenticated SQL Injection via id Parameter
CVE-2014-5180
HDW Player Plugin 2.4.2 - Authenticated SQL Injection via id Parameter
CVE-2014-5089
status2k - Authenticated SQL Injection via log Parameter
CVE-2014-5082
sphider < 1.3.6 - SQL Injection via site_id or url Parameter
CVE-2014-3055
IBM WebSphere Portal 7.x and 8.x through 8.0.0.1 CF12 - SQL Injection
CVE-2014-5109
Fonality trixbox - SQL Injection via mac Parameter in endpoint_generic.php
CVE-2014-5104
ol-commerce 2.1.1 - SQL Injection via Multiple Parameters
CVE-2014-4858
Sabre AirCentre Crew <2010.2.12.20008 - SQL Injection
CVE-2014-3326
Cisco Security Manager 4.5-4.6 - Authenticated SQL Injection
CVE-2014-5102
vBulletin 5.0.4-5.1.3 Alpha 5 - SQL Injection via criteria[startswith] Parameter
CVE-2014-4736
blogengine e2 < 2.4 - SQL Injection via note-id Parameter
CVE-2014-5017
LimeSurvey 2.05+ Build 140618 - SQL Injection via sidx Parameter in Participants JSON Request
CVE-2014-4960
Joomla! com_youtubegallery <4.1.7 - SQL Injection
CVE-2014-4977
Dell SonicWall Scrutinizer 11.0.1 - SQL Injection
CVE-2014-4944
BSK PDF Manager 1.3.2 - SQL Injection
CVE-2014-4013
Aruba Networks ClearPass <6.3.4 - SQL Injection
CVE-2014-4939
ENL Newsletter <1.0.1 - SQL Injection
CVE-2014-4938
WP Rss Poster <1.0.0 - SQL Injection
CVE-2014-3992
Dolibarr ERP/CRM <3.5.3 - SQL Injection
CVE-2014-4852
The Digital Craft AtomCMS - SQL Injection
CVE-2014-4850
FoeCMS - SQL Injection via i Parameter
CVE-2014-4741
Artifectx xClassified 1.2 - SQL Injection
CVE-2014-4194
ZeroCMS 1.0 - SQL Injection via article_id Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High