Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)

4,444
CRITICAL
7,116
HIGH
4,287
MEDIUM
104
LOW
16,171 CVEs · Page 320/324
9.8
CVE-2017-17621

Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.

9.8
CVE-2017-17622

Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

9.8
CVE-2017-17623

Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.

9.8
CVE-2017-17624

PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o

9.8
CVE-2017-17625

Professional Service Script 1.0 has SQL Injection via the service-list city parameter.

9.8
CVE-2017-17626

Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.

9.8
CVE-2017-17627

Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.

9.8
CVE-2017-17628

Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.

9.8
CVE-2017-17629

Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d

9.8
CVE-2017-17630

Yoga Class Script 1.0 has SQL Injection via the /list city parameter.

9.8
CVE-2017-17631

Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.

9.8
CVE-2017-17632

Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

9.8
CVE-2017-17633

Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php

9.8
CVE-2017-17634

Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

9.8
CVE-2017-17635

MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve

9.8
CVE-2017-17636

MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.

9.8
CVE-2017-17637

Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

9.8
CVE-2017-17638

Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.

9.8
CVE-2017-17639

Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.

9.8
CVE-2017-17640

Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa

9.8
CVE-2017-17641

Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.

9.8
CVE-2017-17642

Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.

9.8
CVE-2017-17648

Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid para

9.8
CVE-2017-17713

Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTT

9.8
CVE-2017-17730

DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

9.8
CVE-2017-17731

DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

9.8
CVE-2017-17643

FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.

9.8
CVE-2017-17645

Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.

9.8
CVE-2017-17651

Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para

9.8
CVE-2017-17721

CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass

9.8
CVE-2017-15875

SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL comman

9.8
CVE-2017-17779

Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.

9.8
CVE-2012-2576

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof

9.8
CVE-2017-17870

The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

9.8
CVE-2017-17871

The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action

9.8
CVE-2017-17872

The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

9.8
CVE-2017-17873

Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

9.8
CVE-2017-17875

The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

9.8
CVE-2017-17892

Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search pa

9.8
CVE-2017-17895

Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.

9.8
CVE-2017-17897

SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute a

9.8
CVE-2017-17899

SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers

9.8
CVE-2017-17900

SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbi

9.8
CVE-2017-17906

PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.

9.8
CVE-2017-17928

PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.

9.8
CVE-2017-17931

PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.

9.8
CVE-2017-17951

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.

9.8
CVE-2017-17957

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.

9.8
CVE-2017-17959

PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.

9.8
CVE-2014-4914

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows re

Frequently Asked Questions

What is CWE-89?

CWE-89 (Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-89?

There are 24,110 CVE records associated with CWE-89 in our database. Of these, 4444 are critical severity, 7116 are high severity, and 4287 are medium severity.

How can I protect against CWE-89 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-89 using AI-powered security agents.

Detect CWE-89 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an sql command (sql injection) vulnerabilities across your infrastructure.

Get Started