CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2012-5894
Havalite CMS < 1.1.0 - SQL Injection via postId Parameter
CVE-2012-4951
VeriFone VeriCentre Web Console <2.2.36 - SQL Injection
CVE-2012-4949
ESRI ArcGIS Server 10.1 - Authenticated SQL Injection via REST Service Query Where Parameter
CVE-2012-5453
ATutor AContent <1.2 - SQL Injection
CVE-2012-5167
ATutor AContent <1.2 - SQL Injection
CVE-2012-4990
OpenX 2.8.10 - SQL Injection via ids[] Parameter
CVE-2012-4772
Subrion CMS < 2.2.3 - SQL Injection via Register Plan ID Parameter
CVE-2012-4232
jcore < 1.0 - SQL Injection via memberloginid Cookie
CVE-2012-5350
Pay With Tweet <1.2 - SQL Injection
CVE-2012-5348
MangosWeb Enhanced 3.0.3 - SQL Injection
CVE-2012-5342
SenseSites CommonSense CMS - SQL Injection
CVE-2012-5334
Pre Printing Press - SQL Injection via product_desc.php pid Parameter
CVE-2012-5333
Pre Printing Press - SQL Injection via id Parameter
CVE-2012-5328
Mingle Forum plugin <1.0.33 - SQL Injection
CVE-2012-5327
Mingle Forum plugin 1.0.32.1-1.0.33 - SQL Injection
CVE-2012-5317
Bigware Shop <2.1.5 - SQL Injection
CVE-2012-5313
Snitz Forums 2000 - SQL Injection via TOPIC_ID Parameter
CVE-2012-5312
tribiq CMS - SQL Injection via id Parameter
CVE-2012-5310
WP e-Commerce <3.8.7.6 - SQL Injection
CVE-2012-5300
MyStore Xpress Tienda Virtual 2.0 - SQL Injection
CVE-2012-5297
Mavili Guestbook - SQL Injection via edit.asp id Parameter
CVE-2012-5294
MyStore Xpress Tienda Virtual - SQL Injection
CVE-2012-5292
Atar2b CMS 4.0.1 - SQL Injection via id Parameter
CVE-2012-5291
Posse Softball Director CMS - SQL Injection
CVE-2012-5290
EasyWebRealEstate - SQL Injection via lstid or infoid Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High