CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2014-2948
Bizagi Business Process Management Suite <= 10.4 - Authenticated SQL Injection via SOAP Request
CVE-2014-3783
Dotclear < 2.6.3 - Authenticated SQL Injection via categories_order Parameter
CVE-2014-3210
Booking System < 1.3 - Authenticated SQL Injection via booking_form_id Parameter
CVE-2014-3749
Construtiva CIS Manager - SQL Injection via Email Parameter
CVE-2014-2351
CSWorks <2.5.5233.0 - SQL Injection
CVE-2014-3759
si_bibtex 0.2.3 - SQL Injection via Search or List Functionality
CVE-2014-3757
phpmanufaktur kitform < 0.43 - SQL Injection via sorter_value Parameter
CVE-2014-0137
Red Hat CloudForms Management Engine <5.2.3.2 - SQL Injection
CVE-2014-3246
Collabtive 1.2 - Authenticated SQL Injection via Folder Parameter
CVE-2014-2934
Caldera 9.20 - SQL Injection via tr Parameter
CVE-2014-3138
Xerox DocuShare - Authenticated SQL Injection via PATH_INFO to ResultBackgroundJobMultiple
CVE-2014-2736
MODX Revolution < 2.2.14 - SQL Injection via Session ID or User/ID Parameters
CVE-2014-2737
KnowledgeTree <= 3.7.0.2 - SQL Injection via u Parameter
CVE-2014-2654
MobFox mAdserve <=2.0 - SQL Injection
CVE-2014-0763
Advantech WebAccess < 7.1 - SQL Injection via DBVisitor.dll SOAP Interface
CVE-2014-2847
CIS Manager CMS - SQL Injection via TroncoID Parameter
CVE-2014-2540
OrbitScripts Orbit Open Ad Server <1.1.1 - SQL Injection
CVE-2014-2708
Cacti 0.8.7g and 0.8.8b - SQL Injection via graph_xport.php Parameters
CVE-2014-1455
Pearson eSIS Enterprise Student Information System < 3.3.0.13 - SQL Injection via Password Reset
CVE-2014-2655
Postfix Admin <2.3.7 - SQL Injection
CVE-2014-1645
Symantec LUA <2.3.2.110 - SQL Injection
CVE-2014-2587
McAfee Asset Manager 6.6 - SQL Injection
CVE-2014-1609
MantisBT <1.2.16 - SQL Injection
CVE-2014-2339
GNUboard 5.x - Authenticated SQL Injection via Subject or Content Parameter
CVE-2014-1608
MantisBT < 1.2.16 - SQL Injection via SOAP mc_issue_attachment_get Request
Details
Vulnerabilities
19,915
Exploit Likelihood
High