← Back
CWE-89

20,741 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,741)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Dec 3, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via th...Show more
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.Show less
1Advanced Comment System Project
1Advanced Comment System
Nov 21, 2024
Nov 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing...Show more
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued.Show less
1Cisco
1Prime License Manager
Nov 21, 2024
Nov 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of...Show more
A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted HTTP POST requests that contain malicious SQL statements to an affected application. A successful exploit could allow the attacker to modify and delete arbitrary data in the PLM database or gain shell access with the privileges of the postgres user.Show less
1Terra Master
1Terramaster Operating System
Nov 21, 2024
Nov 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.
1Nuuo
1Nuuo Cms
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.
1Cuppacms
1Cuppacms
Nov 21, 2024
Nov 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.
1Arcms Project
1Arcms
Nov 21, 2024
Nov 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.
1Arcms Project
1Arcms
Nov 21, 2024
Nov 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.
1Interspire
1Email Marketer
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php
1Interspire
1Email Marketer
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
1Interspire
1Email Marketer
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.
1Interspire
1Email Marketer
Nov 21, 2024
Nov 26, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.
1Hucart
1Hucart
Nov 21, 2024
Nov 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the user/index.php?load=login&act=act_login URI.
1Weberp
1Weberp
Nov 21, 2024
Nov 22, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.
1Weberp
1Weberp
Nov 21, 2024
Nov 22, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.
1Weberp
1Weberp
Nov 21, 2024
Nov 22, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.
1Seacms
1Seacms
Nov 21, 2024
Nov 17, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
1S Cms
1S Cms
Nov 21, 2024
Nov 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.
1Centreon
1Centreon
Nov 21, 2024
Nov 16, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.
1School Equipment Monitoring System Project
1School Equipment Monitoring System
Nov 21, 2024
Nov 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.