CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2012-6519
diy-cms 1.0 - SQL Injection via Poll Module start Parameter
CVE-2012-6516
PHP Ticket System Beta 1 - SQL Injection via q Parameter
CVE-2012-6507
ChurchCMS 0.0.1 - SQL Injection via uname or pass Parameter
CVE-2012-6504
PHP Volunteer Management 1.0.2 - SQL Injection via id Parameter
CVE-2012-4414
Oracle MySQL < 5.5.28 - Authenticated SQL Injection via Replication Binary Log
CVE-2012-5874
Elite Bulletin Board < 2.1.22 - SQL Injection via PATH_INFO
CVE-2012-6497
Rails < 3.2.10 - SQL Injection
CVE-2012-6496
Ruby on Rails < 3.0.18, 3.1.x < 3.1.9, 3.2.x < 3.2.10 - SQL Injection via Dynamic Finders
CVE-2012-3873
Openconstructor - SQL Injection
CVE-2012-5590
Drupal Webmail Plus - SQL Injection
CVE-2012-6427
Carlo Gavazzi EOS-Box < 1.0.0.1080_2.1.10 - Unauthenticated SQL Injection
CVE-2012-5967
Centreon 2.3.3-2.3.9-4 - Authenticated SQL Injection via menuXML.php menu Parameter
CVE-2012-4971
Layton Helpbox 4.4.0 - SQL Injection
CVE-2012-5550
Drupal Time Spent <7 - SQL Injection
CVE-2012-5367
OrangeHRM 2.7.1 RC 1 - SQL Injection
CVE-2012-4479
Drag & Drop Gallery 6.x - SQL Injection
CVE-2012-6039
YABSoft Advanced Image Hosting Script - SQL Injection via view_comments.php gal Parameter
CVE-2012-4601
Nicola Asuni TCExam <11.3.009 - SQL Injection
CVE-2012-2086
Gajim < 0.15 - SQL Injection via JIG Parameter
CVE-2012-5861
Sinapsi eSolar, eSolar DUO, and eSolar Light < 2.0.2870_xxx_2.2.12 - Unauthenticated SQL Injection
CVE-2012-4941
Agile FleetCommander <4.08 - SQL Injection
CVE-2012-5912
PicoPublisher 2.0 - SQL Injection via id Parameter
CVE-2012-5910
b2evolution 4.1.3 - Authenticated SQL Injection via Root Parameter
CVE-2012-5909
MyBB 1.6.6 - SQL Injection via conditions[usergroup][] Parameter
CVE-2012-5900
SAMEDIA LandShop 0.9.2 - SQL Injection via OB_ID, AREA_ID, or start Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High