CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2014-2323 CRITICAL
lighttpd < 1.4.35 - SQL Injection via Host Name in mod_mysql_vhost
CVSS 9.8
CVE-2014-2043
Procentia IntelliPen <1.1.18.1658 - SQL Injection
CVE-2014-2311
MODX Revolution <2.2.13 - SQL Injection
CVE-2014-2318
ATCOM Netvolution 3 - SQL Injection
CVE-2014-2317
OpenDocMan <1.2.7.2 - SQL Injection
CVE-2014-2316
Search Everything <7.0.3 - SQL Injection
CVE-2014-1945
OpenDocMan <1.2.7.2 - SQL Injection
CVE-2014-2245
CMS Made Simple < 1.11.10 - Authenticated SQL Injection via News Module sortby Parameter
CVE-2014-2238
MantisBT 1.2.13-1.2.16 - Authenticated SQL Injection via filter_config_id Parameter
CVE-2014-2211
POSH < 3.2.1 - SQL Injection via RSS URL Parameter
CVE-2014-1854
WordPress AdRotate Pro/FREE <3.9.5/3.9.4 - SQL Injection
CVE-2014-1597
synetics i-doit pro <1.2.5 - SQL Injection
CVE-2014-0821
Cybozu Garoon 2.x-2.5.4 and 3.x-3.7 SP3 - Authenticated SQL Injection via Download Feature
CVE-2014-0080
Ruby on Rails <4.0.3 & 4.1.0.beta1 - SQL Injection
CVE-2014-0734
Cisco Unified Communications Manager < 10.0(1) - SQL Injection via CAPF URL
CVE-2014-0729
Cisco Unified Communications Manager - SQL Injection via EMApp Interface URL
CVE-2014-0728
Cisco Unified Communications Manager < 10.0(1) - SQL Injection via Crafted URL
CVE-2014-0727
Cisco Unified Communications Manager - SQL Injection via CMIVR Interface URL
CVE-2014-0726
Cisco Unified Communications Manager < 10.0(1) - SQL Injection via IPMA Interface
CVE-2014-1459
doorGets CMS <= 5.2 - Authenticated SQL Injection via _position_down_id Parameter
CVE-2014-1401
AuraCMS <= 2.3 - Authenticated SQL Injection via Search Parameter or HTTP Headers
CVE-2014-1471
OTRS 3.1.x-3.1.18, 3.2.x-3.2.13, 3.3.x-3.3.3 - SQL Injection via Ticket Search URL
CVE-2014-1204
Tableau Server 8.0.x-8.0.6 and 8.1.x-8.1.1 - Authenticated SQL Injection
CVE-2014-1671
Dell KACE K1000 <5.4.76847 - SQL Injection
CVE-2014-1636
Command School Student Management System 1.06.01 - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High