CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2013-5117
zldnn dnnarticle < 10.0 - SQL Injection via categoryid Parameter
CVE-2013-4467
VICIDIAL < 2.7 - SQL Injection via Campaign Variable in SCRIPT_multirecording_AJAX.php
CVE-2013-3961
Simple PHP Agenda < 2.2.9 - Authenticated SQL Injection via edit_event.php eventid Parameter
CVE-2013-2046
owncloud_server 4.5.x-5.x - Authenticated SQL Injection
CVE-2013-2045
owncloud_server 5.0.x - Authenticated SQL Injection
CVE-2013-1893
owncloud < 5.0.0 - Authenticated SQL Injection in Contacts Application
CVE-2013-3478
Apptha WordPress Video Gallery 2.0 and earlier - SQL Injection via playid Parameter
CVE-2013-6331
IBM Algo One 4.7.0-5.0.0 - Authenticated SQL Injection
CVE-2013-6302
IBM Algo One 4.7.0-5.0.0 - Authenticated SQL Injection
CVE-2013-2498
SimpleHRM <= 2.3 - SQL Injection via Username Parameter
CVE-2013-5015
Symantec Endpoint Protection Manager 11.0-11.0.7405.1424 and 12.1-12.1.4023.4080 - Authenticated SQL Injection
CVE-2013-3294
Exponent CMS <2.2.0 - SQL Injection
CVE-2013-5012
Symantec Web Gateway <5.2 - SQL Injection
CVE-2013-1852
LeagueManager < 3.8.1 - SQL Injection via league_id Parameter
CVE-2013-4887
Digital Signage Xibo 1.4.2 - SQL Injection
CVE-2013-4662
CiviCRM 4.2.0-4.2.9 and 4.3.0-4.3.3 - Authenticated SQL Injection via Quick Search API
CVE-2013-6931
Cybozu Garoon 3.7.x < 3.7.3 - Authenticated SQL Injection
CVE-2013-6930
Cybozu Garoon SQL Injection (2.0.0-2.0.6, 2.1.0-2.1.3, 2.5.0-2.5.4, 3.0.0-3.0.3, 3.5.0-3.5.5, 3.7.x < 3.7.3)
CVE-2013-7175
Avanset Visual CertExam Manager <3.3 - SQL Injection
CVE-2013-7219
Joomla! com_sexypolling <1.0.9 - SQL Injection
CVE-2013-2594
Hornbill Supportworks ITSM <3.4.14 - SQL Injection
CVE-2013-6872
Collabtive < 1.2 - Authenticated SQL Injection via managetimetracker.php id Parameter
CVE-2013-2050
Red Hat CloudForms 5.1 / ManageIQ <=5.0 SQL Injection via miq_policy Profile
CVE-2013-6321
IBM Atlas Suite - SQL Injection
CVE-2013-7139
Horizon Quick Content Management System <= 4.0 - SQL Injection via Download Category Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High