CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2012-2661
Ruby on Rails <3.0.13, <3.1.5, <3.2.4 - SQL Injection
CVE-2012-2171
IBM DS Storage Manager < 10.83 Authenticated SQL Injection
CVE-2012-3791
Simple Web Content Management System 1.1 - SQL Injection via id or status Parameter
CVE-2012-2718
Counter module for Drupal - SQL Injection via Visit Recording
CVE-2012-1815
Emerson DeltaV/Workstations 9.3.1-11.3.1 & ProEssentials 5.0.0.6 SQL Injection
CVE-2012-2762
Serendipity < 1.6.1 - SQL Injection via URL Parameter to comment.php
CVE-2012-0805
SQLAlchemy <0.7.0b4 - SQL Injection
CVE-2012-1255
Segue < 2.2.10.2 - SQL Injection
CVE-2012-2952
Jaow < 2.4.5 - SQL Injection via add_ons Parameter
CVE-2012-2937
Pligg CMS - SQL Injection via Multiple Admin Parameters
CVE-2012-2925
Simple PHP Agenda 2.2.8 - SQL Injection
CVE-2012-2923
Hypermethod eLearning Server 4G - SQL Injection
CVE-2012-2338
Galette 0.63-0.64rc1 - SQL Injection via id_adh Parameter
CVE-2012-2908
Viscacha 0.8.1.1 - SQL Injection via bbcodeexample, buttonimage, or bbcodetag Parameter
CVE-2012-2311
PHP < 5.3.13 and 5.4.x < 5.4.3 - Remote Code Execution via CGI Query String
CVE-2012-2007
HP Performance Insight for Networks 5.3.x, 5.41, 5.41.001, and 5.41.002 - SQL Injection
CVE-2012-0337
Cisco Unified MeetingPlace 7.1 - SQL Injection
CVE-2012-2236
PHP Gift Registry 1.5.5 - Authenticated SQL Injection via UserID Parameter
CVE-2012-0036
curl and libcurl 7.2x < 7.24.0 - Data Injection via URL Pathname Extraction
CVE-2012-1673
e-ticketing - SQL Injection via Login Script Password Parameter
CVE-2012-1672
Hotel Booking Portal 0.1 - SQL Injection via Country Parameter
CVE-2012-1777
F5 FirePass 6.0.0-6.1.0, 7.0.0 - SQL Injection via my.activation.php3 State Parameter
CVE-2012-0226
Invensys Wonderware Information Server 4.0 SP1 and 4.5 - SQL Injection
CVE-2012-0401
EMC RSA enVision <4.1 - SQL Injection
CVE-2012-1784
myjoblist 0.1.3 - SQL Injection via eid Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High