Vulnerabilities > Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-1183 SQL Injection vulnerability in IBM Tivoli Monitoring 6.2.2.9/6.2.3.5/6.3.0.7
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used.
high complexity
ibm CWE-89
7.5
2017-07-17 CVE-2017-11354 SQL Injection vulnerability in Fiyo CMS 2.0.7
Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name.
network
low complexity
fiyo CWE-89
critical
9.8
2017-07-17 CVE-2017-11329 SQL Injection vulnerability in Glpi-Project Glpi
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
network
low complexity
glpi-project CWE-89
critical
9.8
2017-07-17 CVE-2017-1000067 SQL Injection vulnerability in Modx Revolution
MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
network
low complexity
modx CWE-89
8.8
2017-07-17 CVE-2017-1000060 SQL Injection vulnerability in Eyesofnetwork 5.10
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
network
low complexity
eyesofnetwork CWE-89
critical
9.8
2017-07-17 CVE-2017-1000031 SQL Injection vulnerability in Cacti 0.8.8B
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.
network
low complexity
cacti CWE-89
8.8
2017-07-17 CVE-2017-1000004 SQL Injection vulnerability in Atutor
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.
network
low complexity
atutor CWE-89
critical
9.8
2017-07-13 CVE-2017-11200 SQL Injection vulnerability in Finecms Project Finecms
SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter.
network
low complexity
finecms-project CWE-89
8.8
2017-07-12 CVE-2017-11174 SQL Injection vulnerability in Xoops 2.5.8.1
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses.
network
low complexity
xoops CWE-89
critical
9.8
2017-07-09 CVE-2017-8002 SQL Injection vulnerability in EMC Data Protection Advisor
EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities.
network
low complexity
emc CWE-89
8.8