← Back
CWE-89

20,740 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,740)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emlsoft Project
1Emlsoft
Nov 21, 2024
Aug 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in EMLsoft 5.4.5. upload\eml\action\action.address.php has SQL Injection via the numPerPage parameter.
1Emlsoft Project
1Emlsoft
Nov 21, 2024
Aug 6, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in EMLsoft 5.4.5. upload\eml\action\action.user.php has SQL Injection via the numPerPage parameter.
1Zzcms
1Zzcms
Nov 21, 2024
Aug 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
dl/dl_sendmail.php in zzcms 8.3 has SQL Injection via the sql parameter.
1Ocsinventory Ng
1Ocsinventory Ng
Nov 21, 2024
Aug 4, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.
1Pycsw
1Pycsw
Nov 21, 2024
Aug 1, 2018
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL...Show more
A SQL injection vulnerability in pycsw all versions before 2.0.2, 1.10.5 and 1.8.6 that leads to read and extract of any data from any table in the pycsw database that the database user has access to. Also on PostgreSQL (at least) it is possible to perform updates/inserts/deletes and database modifications to any table the database user has access to.Show less
1Seeddms
1Seeddms
Nov 21, 2024
Jul 31, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query within the application by sending additio...Show more
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query within the application by sending additional SQL commands to the application server. An attacker can use this vulnerability to perform malicious tasks such as to extract, change, or delete sensitive information within the database supporting the application, and potentially run system commands on the underlying operating system.Show less
1Cybozu
1Garoon
Nov 21, 2024
Jul 26, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
1Zte
1Zxiptv Ucm Firmware
Nov 21, 2024
Jul 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database...Show more
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.Show less
1Zte
1Zxcdn Sns Firmware
Nov 21, 2024
Jul 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database infor...Show more
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.Show less
1Navarino
1Infinity
Jun 17, 2026
Jul 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could...Show more
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication.Show less
1Tibco
7Spotfire Analyst
Spotfire ClientSpotfire Connectors+4 more
Nov 21, 2024
Jul 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an at...Show more
Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The following products and versions are affected: TIBCO Spotfire Analyst 7.7.0 TIBCO Spotfire Connectors 7.6.0 TIBCO Spotfire Deployment Kit 7.7.0 TIBCO Spotfire Desktop 7.6.0 TIBCO Spotfire Desktop 7.7.0 TIBCO Spotfire Desktop Developer Edition 7.7.0 TIBCO Spotfire Desktop Language Packs 7.6.0 TIBCO Spotfire Desktop Language Packs 7.7.0 The following components are affected: TIBCO Spotfire Client TIBCO Spotfire Web Player ClientShow less
1Wuzhi Cms Project
1Wuzhi Cms
Nov 21, 2024
Jul 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter.
1Joyplus Project
1Joyplus Cms
Nov 21, 2024
Jul 22, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.
1Wuzhicms
1Wuzhicms
Nov 21, 2024
Jul 20, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
1Msvod
1Msvod Cms
Nov 21, 2024
Jul 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
1Ssh Companywebsite Project
1Ssh Companywebsite
Nov 21, 2024
Jul 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
1Joyplus Cms Project
1Joyplus Cms
Nov 21, 2024
Jul 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
1Google
1Android
Nov 21, 2024
Jul 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can...Show more
The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.Show less
1Sungardas
1Etrakit3
Nov 21, 2024
Jul 13, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote att...Show more
The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.Show less
1Wolfsight
1Wolfsight Cms
Nov 21, 2024
Jul 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.