Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 318/324
9.8
CVE-2017-15958

D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.

9.8
CVE-2017-15959

Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-200

9.8
CVE-2017-15960

Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.

9.8
CVE-2017-15961

iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.

9.8
CVE-2017-15963

iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser pa

9.8
CVE-2017-15964

Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.

9.8
CVE-2017-15965

The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in

9.8
CVE-2017-15966

The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parame

9.8
CVE-2017-15967

Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the e

9.8
CVE-2017-15968

MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.

9.8
CVE-2017-15969

PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_cata

9.8
CVE-2017-15970

PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.

9.8
CVE-2017-15971

Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php send

9.8
CVE-2017-15972

SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php

9.8
CVE-2017-15973

Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.

9.8
CVE-2017-15974

tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.

9.8
CVE-2017-15975

Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability

9.8
CVE-2017-15976

ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-200

9.8
CVE-2017-15977

Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.

9.8
CVE-2017-15978

AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.

9.8
CVE-2017-15979

Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.

9.8
CVE-2017-15980

US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.

9.8
CVE-2017-15981

Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for fo

9.8
CVE-2017-15982

Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editi

9.8
CVE-2017-15983

MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing

9.8
CVE-2017-15984

Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.

9.8
CVE-2017-15985

Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.

9.8
CVE-2017-15986

CPA Lead Reward Script allows SQL Injection via the username parameter.

9.8
CVE-2017-15987

Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.

9.8
CVE-2017-15988

Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008

9.8
CVE-2017-15989

Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.

9.8
CVE-2017-15991

Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type

9.8
CVE-2017-15992

Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.

9.8
CVE-2017-15993

Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.

9.8
CVE-2017-14356

An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch

9.8
CVE-2017-16510

WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading t

9.8
CVE-2017-16543

Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated

9.8
CVE-2017-16561

/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL i

9.8
CVE-2015-3933

Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote

9.8
CVE-2017-16846

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=

9.8
CVE-2017-16847

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid pa

9.8
CVE-2017-16848

Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.

9.8
CVE-2017-16849

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoar

9.8
CVE-2017-16850

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid pa

9.8
CVE-2017-16851

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.

9.8
CVE-2017-16896

A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login par

9.8
CVE-2015-3934

Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi

9.8
CVE-2017-10898

SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to e

9.8
CVE-2017-10899

SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to

9.8
CVE-2017-17110

Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started