← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Baijiacms Project
1Baijiacms
Nov 21, 2024
Sep 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in th...Show more
IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM X-Force ID: 148599.Show less
1Jorani Project
1Jorani
Nov 21, 2024
Sep 5, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startda...Show more
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.Show less
1Gxlcms
1Gxlcms
Nov 21, 2024
Sep 5, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
1Seacms
1Seacms
Nov 21, 2024
Sep 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.
1Bluecms Project
1Bluecms
Nov 21, 2024
Sep 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login.
1Vanillaforums
1Vanilla
Nov 21, 2024
Sep 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecon...Show more
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php.Show less
1Thinkphp
1Thinkphp
Nov 21, 2024
Sep 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
1Owasp
1Owasp Modsecurity Core Rule Set
Nov 21, 2024
Sep 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be e...Show more
A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.Show less
1Fhcrm Project
1Fhcrm
Nov 21, 2024
Sep 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter.
1Fhcrm Project
1Fhcrm
Nov 21, 2024
Sep 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter.
1Phpkaiyuancms
1Phpopensourcecms
Nov 21, 2024
Aug 31, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.
1Codemenschen
1Gift Vouchers
Nov 21, 2024
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.
2Broadcom
Ca
2Project Portfolio Management
Project Portfolio Management
Nov 21, 2024
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.
1Sapplica
1Sentrifugo
Nov 21, 2024
Aug 28, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.
1Phpmyfaq
1Phpmyfaq
Nov 21, 2024
Aug 28, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.
1A10networks
1Acos Web Application Firewall
Nov 21, 2024
Aug 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A...Show more
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A10-2017-0008.Show less
1Wuzhi Cms Project
1Wuzhi Cms
Nov 21, 2024
Aug 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter.
1Wuzhi Cms Project
1Wuzhi Cms
Nov 21, 2024
Aug 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter.
1Rsa
1Archer
Nov 21, 2024
Aug 24, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contains a SQL injection vulnerability. A malicious user could potentially exploit t...Show more
The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contains a SQL injection vulnerability. A malicious user could potentially exploit this vulnerability to execute SQL commands on the back-end database to read certain data. Embedded WorkPoint is upgraded to version 4.10.16, which contains a fix for the vulnerability.Show less