CWE-89
20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,740)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Baijiacms Project 1Baijiacms Nov 21, 2024 Sep 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request. |
1Ibm 1Security Identity Governance And Intelligence Nov 21, 2024 Sep 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Identity Governance and Intelligence 5.2.3.2 and 5.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in th...Show more |
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startda...Show more |
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. |
An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request. |
BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login. |
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecon...Show more |
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string. |
1Owasp 1Owasp Modsecurity Core Rule Set Nov 21, 2024 Sep 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be e...Show more |
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter. |
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter. |
1Phpkaiyuancms 1Phpopensourcecms Nov 21, 2024 Aug 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter. |
1Codemenschen 1Gift Vouchers Nov 21, 2024 Aug 30, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. |
2Broadcom Ca2Project Portfolio Management Project Portfolio ManagementNov 21, 2024 Aug 30, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks. |
A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter. |
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function. |
1A10networks 1Acos Web Application Firewall Nov 21, 2024 Aug 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL injection attacks, aka A...Show more |
1Wuzhi Cms Project 1Wuzhi Cms Nov 21, 2024 Aug 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter. |
1Wuzhi Cms Project 1Wuzhi Cms Nov 21, 2024 Aug 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter. |
The WorkPoint component, which is embedded in all RSA Archer, versions 6.1.x, 6.2.x, 6.3.x prior to 6.3.0.7 and 6.4.x prior to 6.4.0.1, contains a SQL injection vulnerability. A malicious user could potentially exploit t...Show more |