CWE-89
20,711 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,711)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query. |
1Eyesofnetwork 1Eyesofnetwork May 13, 2026 Sep 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php. |
1Eyesofnetwork 1Eyesofnetwork May 13, 2026 Sep 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/...Show more |
1Eyesofnetwork 1Eyesofnetwork May 13, 2026 Sep 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section. |
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php. |
EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system. |
SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php. |
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in up...Show more |
1User Dashboard Project 1User Dashboard May 13, 2026 Sep 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors. |
1Eyesofnetwork 1Eyesofnetwork May 13, 2026 Sep 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the group_id cookie to side.php. |
1Eyesofnetwork 1Eyesofnetwork May 13, 2026 Sep 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060. |
SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter. |
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter. |
1Opwglobal 3Sitesentinel Integra 100 Firmware Sitesentinel Integra 500 FirmwareSitesentinel Isite Atg FirmwareMay 13, 2026 Sep 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189...Show more |
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type paramete...Show more |
A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-su...Show more |
SQL injection vulnerability in Sefrengo before 1.6.5 beta2. |
SQL injection vulnerability in Concrete5 5.7.3.1. |
1Pragyan Cms Project 1Pragyan Cms May 13, 2026 Sep 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in Pragyan CMS 3.0. |
1Tune Library Project 1Tune Library May 13, 2026 Sep 7, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5. |