CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2013-2956
IBM InfoSphere Optim Data Growth - SQL Injection
CVE-2013-3537
Todoo Forum 2.0 - SQL Injection via id_post or pg Parameter
CVE-2013-3536
WHMCS Group Pay < 1.5 - SQL Injection via Hash Parameter
CVE-2013-3533
Virtual Access Monitor < 3.10.17 - SQL Injection
CVE-2013-3532
Spider Video Player 2.1 - SQL Injection via Theme Parameter
CVE-2013-3531
RadioCMS 2.2 - SQL Injection via meneger.php playlist_id Parameter
CVE-2013-3530
Spiffy XSPF Player plugin 0.1 - SQL Injection via playlist_id Parameter
CVE-2013-3527
Vanilla Forums < 2.0.18.8 - SQL Injection via Form/Email Parameter
CVE-2013-3525
Request Tracker < 4.0.9 - SQL Injection via ShowPending Parameter
CVE-2013-3524
Pop Up News module 2.0 - SQL Injection via itemid Parameter
CVE-2013-3523
This HTML Is Simple < 1.2.4 - SQL Injection via op=page&id= URL Parameter
CVE-2013-3522
vBulletin 5.0.0 Beta 11 and earlier - Authenticated SQL Injection via nodeid Parameter
CVE-2013-0684
Invensys Wonderware WIS <5.0 - SQL Injection
CVE-2013-3510
GroundWork Monitor Enterprise 6.7.0 - Authenticated SQL Injection via System-Export.php
CVE-2013-0140
McAfee ePolicy Orchestrator < 4.5.7 and 4.6.x < 4.6.6 - SQL Injection via Agent-Handler Component
CVE-2013-1177
Cisco NAC <4.8.3.1-4.9.2 - SQL Injection
CVE-2013-1748
PHP Address Book 8.2.5 - SQL Injection via edit.php or import.php Parameters
CVE-2013-3050
ZAPms < 1.41 - SQL Injection via Product PID Parameter
CVE-2013-0135
PHP Address Book 8.2.5 - SQL Injection via Multiple Parameters
CVE-2013-1163
Cisco Connected Grid Network Management System - SQL Injection
CVE-2013-0511
IBM Security AppScan Enterprise <8.7 - SQL Injection
CVE-2013-2690
Synchroweb SynConnect 2.0 - SQL Injection via LoginID Parameter
CVE-2013-0123
askiaweb - SQL Injection via nHistoryId or OrderBy Parameter
CVE-2013-1842
TYPO3 4.5.x-4.6.x-4.7.x-6.0.x - SQL Injection via Query Object Model
CVE-2013-0701
Cybozu Garoon <3.5.3 - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High