CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2013-4953
Top Games Script 1.2 - SQL Injection
CVE-2013-4952
elemata_cms RC 3.0 - SQL Injection via id Parameter
CVE-2013-4948
Machform 2 - SQL Injection via element_2 Parameter
CVE-2013-4945
BMC Service Desk Express 10.2.1.95 - SQL Injection
CVE-2013-3033
IBM Tivoli Remote Control <5.1.2 - SQL Injection
CVE-2013-3437
Cisco Unified Operations Manager - Authenticated SQL Injection via Entry Field
CVE-2013-4882
McAfee ePolicy Orchestrator <4.6.6 - SQL Injection
CVE-2013-4870
TYPO3 news_search 0.1.0 - SQL Injection
CVE-2013-3412
Cisco Unified Communications Manager 7.1-9.1(2) - Authenticated SQL Injection
CVE-2013-3404
Cisco Unified Communications Manager 7.1-9.1(1a) - SQL Injection
CVE-2013-3578
Wave EMBASSY Remote Admin Server Help Desk SQLi & OS Command Execution via Search
CVE-2013-3577
Wave EMBASSY Remote Administration Server Help Desk - SQL Injection via Search Field Parameter
CVE-2013-1613
Symantec Security Information Manager 4.7.x-4.8.x - Authenticated SQL Injection
CVE-2013-0560
IBM Sterling B2B Integrator <5.3 - SQL Injection
CVE-2013-4748
News < 1.3.3 - SQL Injection
CVE-2013-4745
My quiz and poll <2.0.6 - SQL Injection
CVE-2013-4721
TYPO3 records extension <1.0.0 - SQL Injection
CVE-2013-4720
TYPO3 WEC Discussion Forum <2.1.2 - SQL Injection
CVE-2013-4719
TYPO3 tt_news <1.3.3 - SQL Injection
CVE-2013-4683
TYPO3 meta_feedit <0.1.10 - SQL Injection
CVE-2013-4682
Multishop < 2.0.39 - SQL Injection
CVE-2013-4681
TYPO3 Sofortueberweisung2commerce <2.0.1 - SQL Injection
CVE-2013-4634
TYPO3 rzautocomplete <0.0.9 - SQL Injection
CVE-2013-3957
SIMATIC PCS7 < 8.0 and WinCC < 7.2 - SQL Injection via Login Screen
CVE-2013-3721
PsychoStats 3.2.2b - SQL Injection via Awards Page d Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High