← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gxlcms
1Gxlcms
Nov 21, 2024
Oct 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.
1Phpshe
1Phpshe
Nov 21, 2024
Oct 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.
1Koha
1Koha
Nov 21, 2024
Oct 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number par...Show more
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.Show less
1Pbootcms
1Pbootcms
Nov 21, 2024
Oct 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI.
1S Cms
1S Cms
Nov 21, 2024
Oct 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.
1Cloud Foundry
1Cf Networking
Nov 21, 2024
Oct 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTL...Show more
Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server.Show less
1Youke365
1Youke 365
Nov 21, 2024
Oct 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.
1Pbootcms
1Pbootcms
Nov 21, 2024
Oct 10, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
1Redaxo
1Redaxo
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.
1Comsenz
1Duomicms
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
1Wikidforum Project
1Wikidforum
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.
1Cisco
2Rv180w Wireless N Multifunction Vpn Router
Rv220w Wireless Network Security Firewall
Nov 21, 2024
Oct 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to exe...Show more
A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker could retrieve sensitive information which should be restricted. A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker could retrieve sensitive information which should be restricted. The product has entered the end-of-life phase and there will be no more firmware fixes.Show less
1Ibm
1Financial Transaction Manager
Nov 21, 2024
Oct 4, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow th...Show more
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 150023.Show less
1Suse
1Subscription Management Tool
Nov 21, 2024
Oct 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection in the RegistrationSharing module of SUSE Linux SMT allows remote attackers to cause execute arbitrary SQL statements. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.
1Multitech
1Faxfinder
Nov 21, 2024
Oct 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different in...Show more
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.Show less
1Naviwebs
1Navigate Cms
Nov 21, 2024
Oct 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
1Nexusfi
1Opac Easyweb Five
Nov 21, 2024
Oct 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
1Google
1Android
Jun 17, 2026
Oct 2, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User in...Show more
In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900Show less
1Wuzhi Cms Project
1Wuzhi Cms
Nov 21, 2024
Oct 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.
1Redaxo
1Redaxo
Nov 21, 2024
Oct 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endan...Show more
In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the frontend only if rex_list were used.Show less