CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2013-3638 HIGH
Boonex Dolphin < 7.1.3 - Authenticated SQL Injection via Categories Path Parameter
CVSS 8.8
CVE-2013-3932 HIGH
jomres < 7.3.1 - Authenticated SQL Injection via id Parameter
CVSS 8.8
CVE-2013-5743 CRITICAL
Zabbix 1.8-1.8.17 - SQL Injection
CVSS 9.8
CVE-2013-2745 CRITICAL
minidlna < 1.1.0 - SQL Injection
CVSS 9.8
CVE-2013-2091 CRITICAL
Dolibarr ERP/CRM 3.3.1 - SQL Injection via 'pays' Parameter in fiche.php
CVSS 9.8
CVE-2013-2738 CRITICAL
readymedia < 1.1.0 - SQL Injection
CVSS 9.8
CVE-2013-3000 CRITICAL
IBM InfoSphere Data Replication Dashboard <10.1 - SQL Injection
CVSS 9.8
CVE-2013-7406
MRBS module for Drupal - SQL Injection
CVE-2013-6311
IBM Marketing Platform 9.1 - Authenticated SQL Injection
CVE-2013-3081
jojo-cms < 1.2.2 - SQL Injection via X-Forwarded-For Header
CVE-2013-4016
IBM Maximo Asset Management 7.x < 7.1.1.7 LAFIX.20140319-0837 - Authenticated SQL Injection via Birt Report WHERE Clause
CVE-2013-2226
GLPI < 0.83.9 - SQL Injection via users_id_assign, filename, or table Parameter
CVE-2013-7375
PHP-Fusion <7.02.05 - SQL Injection
CVE-2013-1803
php-fusion < 7.02.06 - SQL Injection via Multiple Parameters
CVE-2013-7369
F-Secure Anti-Virus - SQL Injection via FSDBCom ActiveX Control
CVE-2013-7355
SAP BI Universal Data Integration - SQL Injection
CVE-2013-0735
Mingle Forum <1.0.34 - SQL Injection
CVE-2013-2945
b2evolution < 4.1.7 - Authenticated SQL Injection via show_statuses[] Parameter
CVE-2013-3213
vtiger CRM 5.0.0-5.4.0 - SQL Injection via Picklist Name or Email Address Parameter
CVE-2013-7349
Gnew 2013.1 - SQL Injection via news_id, thread_id, or user_email Parameter
CVE-2013-5640
Gnew 2013.1 - SQL Injection via Multiple Parameters
CVE-2013-2559
Symphony CMS <2.3.2 - SQL Injection
CVE-2013-1408
Wysija Newsletters < 2.2.1 - Authenticated SQL Injection via Search or Orderby Parameter
CVE-2013-4058
IBM InfoSphere Information Server 8.x-8.5 FP3, 8.7.x-8.7 FP2, 9.1.x-9.1.2.0 - Authenticated SQL Injection
CVE-2013-3727
Kasseler CMS < 2 - Authenticated SQL Injection via groups[] Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High