CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2013-6936
MyBB Ajax forum stat Plugin 2.0 - SQL Injection via tooltip or usertooltip Parameter
CVE-2013-5957
CiviCRM < 4.2.12, 4.3.x < 4.3.7, 4.4.x < 4.4.beta4 - SQL Injection via _value Parameter
CVE-2013-6875
Nagios XI < 2012r2.4 - SQL Injection via tfPassword Parameter
CVE-2013-6873
Testa Online Test Management System 2.0.0.2 - SQL Injection via test_id Parameter
CVE-2013-6869
SAP NetWeaver 7.30 - SQL Injection via SRTT_GET_COUNT_BEFORE_KEY_RFC Function
CVE-2013-6176
EMC Document Sciences xPression 4.1 SP1-4.5 - Authenticated SQL Injection via xAdmin or xDashboard Form
CVE-2013-4386
Redhat Openstack < 1.2.2 - SQL Injection
CVE-2013-6164
projeqtor 3.4.0 - SQL Injection via objectId Parameter
CVE-2013-6058
appRain CMF < 3.0.2 - SQL Injection via PATH_INFO to blog-by-cat/
CVE-2013-4715
Tiki Wiki CMS Groupware <6.13LTS-11.1 - SQL Injection
CVE-2013-5694
Opsview < 4.4.1 - SQL Injection via service_selection Parameter
CVE-2013-6172
Roundcube webmail < 0.8.7 and 0.9.x < 0.9.5 - SQL Injection via _session Parameter
CVE-2013-6243
Landing Pages Plugin < 1.2.3 - SQL Injection via Post Parameter
CVE-2013-4422
Quassel IRC < 0.9.1 - SQL Injection via Backslash in Message
CVE-2013-4827
HP Intelligent Management Center and IMC Service Operation Management Software Module - SQL Injection
CVE-2013-4137
StatusNet 1.0-1.0.1 and 1.1.0 - SQL Injection via User Lists and Tag Format
CVE-2013-5028
Kwoksys Kwok Info Server <2.8.5 - SQL Injection
CVE-2013-5525
Cisco Identity Services Engine Software < 1.2 - Authenticated SQL Injection
CVE-2013-5967
AlienVault OSSIM < 4.3 - SQL Injection via RadarReport Date Parameter
CVE-2013-5091
vtiger CRM < 5.4.0 - Authenticated SQL Injection via onlyforuser Parameter
CVE-2013-5517
Cisco Unified Communications Domain Manager - SQL Injection
CVE-2013-4017
IBM Maximo Asset Management 7.1 - SQL Injection
CVE-2013-3973
IBM Maximo Asset Management 7.1-7.1.1.11 and 7.5-7.5.0.4 - Authenticated SQL Injection
CVE-2013-0451
IBM Maximo Asset Management 6.2-6.2.8 and 7.1-7.1.1.12 - Authenticated SQL Injection
CVE-2013-5697
mod_accounting < 0.5 - SQL Injection via Host Header
Details
Vulnerabilities
19,915
Exploit Likelihood
High