CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,889 vulnerabilities with CWE-89
CVE-2017-20279 HIGH
Joomla Payage 2.05 SQL Injection via aid Parameter
CVSS 8.2
CVE-2017-20278 HIGH
Joomla JoomRecipe 1.0.3 SQL Injection via category parameter
CVSS 8.2
CVE-2017-20277 HIGH
Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
CVSS 8.2
CVE-2017-20276 HIGH
Joomla! Component SIMGenealogy 2.1.5 SQL Injection
CVSS 8.2
CVE-2017-20275 HIGH
Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter
CVSS 8.2
CVE-2017-20274 HIGH
Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
CVSS 8.2
CVE-2017-20273 HIGH
Joomla Event Registration Pro Calendar 4.1.3 SQL Injection
CVSS 8.2
CVE-2017-20272 HIGH
Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
CVSS 8.2
CVE-2017-20271 HIGH
Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
CVSS 8.2
CVE-2017-20270 HIGH
Joomla! Component Twitch Tv 1.1 SQL Injection
CVSS 8.2
CVE-2017-20269 HIGH
Joomla! Component KissGallery 1.0.0 SQL Injection
CVSS 8.2
CVE-2017-20268 HIGH
Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection
CVSS 8.2
CVE-2017-20267 HIGH
Joomla! Component Calendar Planner 1.0.1 SQL Injection
CVSS 8.2
CVE-2017-20266 HIGH
Joomla SP Movie Database 1.3 SQL Injection via searchword
CVSS 8.2
CVE-2017-20265 HIGH
Joomla! Component Flip Wall 8.0 SQL Injection
CVSS 7.1
CVE-2017-20264 HIGH
Joomla! Component Sponsor Wall 8.0 SQL Injection
CVSS 7.1
CVE-2017-20263 HIGH
Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location
CVSS 8.2
CVE-2017-20262 HIGH
Joomla! Component Ajax Quiz 1.8 SQL Injection
CVSS 8.2
CVE-2017-20261 HIGH
Joomla! Component Bargain Product VM3 1.0 SQL Injection
CVSS 8.2
CVE-2017-20260 HIGH
Joomla! Component Price Alert 3.0.2 SQL Injection
CVSS 8.2
CVE-2017-20259 HIGH
Joomla OSDownloads 1.7.4 SQL Injection via item view
CVSS 8.2
CVE-2017-20258 HIGH
Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection
CVSS 8.2
CVE-2017-20257 HIGH
Joomla! Component Quiz Deluxe 3.7.4 SQL Injection
CVSS 8.2
CVE-2017-20256 HIGH
Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
CVSS 8.2
CVE-2017-20255 HIGH
Joomla! Component JB Visa 1.0 SQL Injection via visatype
CVSS 8.2
Details
Vulnerabilities 19,889
Exploit Likelihood High