CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-3483
Ruby on Rails 4.x < 4.0.7 and 4.1.x < 4.1.3 - SQL Injection via PostgreSQL Range Quoting
CVE-2014-3482
Ruby on Rails 2.x and 3.x - SQL Injection via PostgreSQL Bitstring Quoting
CVE-2014-3857
Kerio Control < 8.3.2 - Authenticated SQL Injection via Statistics Print Parameters
CVE-2014-4649
Piwigo 2.6.x and 2.7.x < 2.7.0beta2 - Authenticated SQL Injection via Photo-Edit Associate Field
CVE-2014-4644
Cacti superlinks plugin 1.4-2 - SQL Injection via id Parameter
CVE-2014-3810
BoonEx Dolphin <= 7.1.4 - Authenticated SQL Injection via Members Parameter
CVE-2014-1651
Symantec Web Gateway <5.2 - SQL Injection
CVE-2014-1650
Symantec Web Gateway <5.2.1 - SQL Injection
CVE-2014-2949
F5 ARX Data Manager 3.0.0-3.1.0 - Authenticated SQL Injection
CVE-2014-4307
WebTitan < 4.01 - SQL Injection via categories-x.php sortkey Parameter
CVE-2014-4305
NICE Recording eXpress <6.5.7 - SQL Injection
CVE-2014-2303
webEdition CMS <6.3.8-s1 - SQL Injection
CVE-2014-4034
ZeroCMS 1.0 - SQL Injection via article_id Parameter
CVE-2014-3287
Cisco Unified Communications Manager SQL Injection via BulkViewFileContentsAction.java
CVE-2014-3973
FrontAccounting <2.3.21 - SQL Injection
CVE-2014-3962
Videos Tube 1.0 - SQL Injection via URL Parameter
CVE-2014-3961
WordPress Participants Database <1.5.4.9 - SQL Injection
CVE-2014-3937
WordPress <1.8.10.2 - SQL Injection
CVE-2014-3935
XOOPS 1.0 - Glossaire module - SQL Injection
CVE-2014-3934
PHP-Nuke 8.3 - SQL Injection via Submit_News Module topics[] Parameter
CVE-2014-3932
CoSoSys Endpoint Protector <4.4.0.2 - SQL Injection
CVE-2014-3415
Sharetronix < 3.3 - Authenticated SQL Injection via invite_users[] Parameter
CVE-2014-3872
D-Link DAP-1350 Firmware < 1.14 - SQL Injection via Username or Password
CVE-2014-3871
Geodesic Solutions GeoCore MAX 7.3.3 - SQL Injection via Register.php Parameters
CVE-2014-3275
Cisco Identity Services Engine Software < 1.2 - Authenticated SQL Injection via Crafted URL
Details
Vulnerabilities 19,915
Exploit Likelihood High