CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2013-7278
Naxtech CMS Afroditi 1.0 - SQL Injection
CVE-2013-7262
MapServer < 6.4.1 - SQL Injection via PostGIS TIME Filter
CVE-2013-7225
Fat Free CRM <0.12.1 - SQL Injection
CVE-2013-7242
zenphoto < 1.4.5.4 - Authenticated SQL Injection via WordPress Import Table Prefix
CVE-2013-6983
Cisco Unified Presence Server - Authenticated SQL Injection via Crafted URL
CVE-2013-7232
ESRI ArcGIS for Server < 10.2 - SQL Injection via Map or Feature Service Input
CVE-2013-7149
Revive Adserver <3.0.2 & OpenX Source <=2.8.11 - SQL Injection
CVE-2013-6929
Cybozu Garoon < 3.7 - Authenticated SQL Injection via API Input
CVE-2013-7216
Classifieds Creator 2.0 - SQL Injection
CVE-2013-4461
Red Hat Enterprise MRG Grid 2.4 - SQL Injection via Filtering Table Operator
CVE-2013-5409
IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 - Authenticated SQL Injection
CVE-2013-7193
C2C Forward Auction Creator 2.0 - SQL Injection
CVE-2013-7192
Dynamic Biz Website Builder - SQL Injection
CVE-2013-2627
Leed Light Feed <1.5 - SQL Injection
CVE-2013-7189
iScripts AutoHoster - SQL Injection
CVE-2013-7187
FormCraft < 1.3.7 - SQL Injection via id Parameter
CVE-2013-7096
SAP EMR Unwired - SQL Injection
CVE-2013-7094
SAP NetWeaver 7.30 - SQL Injection via RSDDCVER_COUNT_TAB_COLS Function
CVE-2013-7092
McAfee Email Gateway 7.6 - SQL Injection
CVE-2013-6839
InstantCMS < 1.10.3 - SQL Injection via OrderBy Parameter
CVE-2013-6985
Enorth Webpublisher CMS < 5.0 - SQL Injection via thisday Parameter
CVE-2013-5354
Sharetronix 3.1.1 - SQL Injection via fb_user_id or tw_user_id Parameter
CVE-2013-6787
Chamilo LMS < 1.9.6 - Authenticated SQL Injection via Password Parameter
CVE-2013-6341
Dokeos < 2.2 - SQL Injection via Language Parameter
CVE-2013-6001
Cybozu Garoon < 3.7 SP1 - Authenticated SQL Injection via Space Function
Details
Vulnerabilities 19,915
Exploit Likelihood High