Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 319/324
9.8
CVE-2017-17111

Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail

9.8
CVE-2017-17570

FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o

9.8
CVE-2017-17571

FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.

9.8
CVE-2017-17572

FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.

9.8
CVE-2017-17573

FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p

9.8
CVE-2017-17574

FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.

9.8
CVE-2017-17575

FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.

9.8
CVE-2017-17576

FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se

9.8
CVE-2017-17577

FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param

9.8
CVE-2017-17578

FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.

9.8
CVE-2017-17579

FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.

9.8
CVE-2017-17580

FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.

9.8
CVE-2017-17581

FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.

9.8
CVE-2017-17582

FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.

9.8
CVE-2017-17583

FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.

9.8
CVE-2017-17584

FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.

9.8
CVE-2017-17585

FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.

9.8
CVE-2017-17586

FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.

9.8
CVE-2017-17587

FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c

9.8
CVE-2017-17588

FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par

9.8
CVE-2017-17589

FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parame

9.8
CVE-2017-17590

FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.

9.8
CVE-2017-17591

Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.

9.8
CVE-2017-17592

Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.

9.8
CVE-2017-17594

DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.

9.8
CVE-2017-17595

Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.

9.8
CVE-2017-17596

Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.

9.8
CVE-2017-17597

Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.

9.8
CVE-2017-17598

Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.

9.8
CVE-2017-17599

Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter

9.8
CVE-2017-17600

Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.

9.8
CVE-2017-17601

Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.

9.8
CVE-2017-17602

Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.

9.8
CVE-2017-17603

Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_

9.8
CVE-2017-17604

Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.

9.8
CVE-2017-17605

Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.

9.8
CVE-2017-17606

Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.

9.8
CVE-2017-17607

CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.

9.8
CVE-2017-17608

Child Care Script 1.0 has SQL Injection via the /list city parameter.

9.8
CVE-2017-17609

Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.

9.8
CVE-2017-17610

E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet

9.8
CVE-2017-17611

Doctor Search Script 1.0 has SQL Injection via the /list city parameter.

9.8
CVE-2017-17612

Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.

9.8
CVE-2017-17613

Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati

9.8
CVE-2017-17614

Food Order Script 1.0 has SQL Injection via the /list city parameter.

9.8
CVE-2017-17616

Event Search Script 1.0 has SQL Injection via the /event-list city parameter.

9.8
CVE-2017-17617

Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.

9.8
CVE-2017-17618

Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

9.8
CVE-2017-17619

Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.

9.8
CVE-2017-17620

Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started