CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2013-5931
Real Estate PHP Script - SQL Injection via listingid Parameter
CVE-2013-5917
NOSpam PTI 2.1 - SQL Injection via comment_post_ID Parameter
CVE-2013-4313
Moodle < 2.2.11, 2.3.x < 2.3.9, 2.4.x < 2.4.6, 2.5.x < 2.5.2 - SQL Injection via Null Byte in Query String
CVE-2013-4809
HP ProCurve Manager <4.0 - SQL Injection
CVE-2013-5723
SAP NetWeaver 7.30 - SQL Injection via ABAD0_DELETE_DERIVATION_TABLE
CVE-2013-5673
IndiaNIC Testimonial plugin 2.2 - SQL Injection via custom_query Parameter
CVE-2013-3602
Coursemill Learning Management System 6.6 - Authenticated SQL Injection via docID Parameter
CVE-2013-5589
Cacti <0.8.8b - SQL Injection
CVE-2013-1434
Cacti < 0.8.8b - SQL Injection via api_poller.php and utility.php
CVE-2013-5569
Slideshare extension 0.1.0 - SQL Injection
CVE-2013-5322
CoolURI < 1.0.30 - SQL Injection
CVE-2013-5321
AlienVault OSSIM 4.1 - SQL Injection
CVE-2013-5318
Ginkgo CMS 5.0 - SQL Injection
CVE-2013-5311
Vastal I-Tech phpVID <1.2.3 - SQL Injection
CVE-2013-5310
wfqbe < 2.0.1 - SQL Injection
CVE-2013-5306
TYPO3 browser <4.5.5 - SQL Injection
CVE-2013-5304
TYPO3 locator <3.1.5 - SQL Injection
CVE-2013-5302
TYPO3 ke_search <1.4.1 - SQL Injection
CVE-2013-5121
PHPFox - SQL Injection via search[sort_by] Parameter
CVE-2013-5120
PHPFox - SQL Injection via search[gender] Parameter
CVE-2013-4879
BigTree CMS <4.0 RC2 - SQL Injection
CVE-2013-4789
Cotonti Siena < 0.9.14 - SQL Injection via RSS Module c Parameter
CVE-2013-4619
OpenEMR 4.1.1 - Authenticated SQL Injection via start/end/form_newid Parameters
CVE-2013-1617
Symantec Web Gateway < 5.1.1 - Authenticated SQL Injection
CVE-2013-5003
phpMyAdmin <3.5.8.2, <4.0.4.2 - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High