CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2012-1911
PHP Address Book < 6.2.11 - SQL Injection via to_group or id Parameter
CVE-2012-4868
Kunena 1.7.2 - SQL Injection via News.php ID Parameter
CVE-2012-2740
phplist < 2.10.18 - SQL Injection via sortby Parameter
CVE-2012-2109
BuddyPress 1.5.x < 1.5.5 - SQL Injection via Activity Widget Filter Page Parameter
CVE-2012-4743
Siche search module 0.5 - SQL Injection
CVE-2012-4686
vBulletin 4.1.10 - SQL Injection via Announcement ID Parameter
CVE-2012-1934
Newscoop - SQL Injection via f_country_code Parameter
CVE-2012-4673
NeoInvoice - SQL Injection via sort_col Parameter in list_items Function
CVE-2012-3477
NeoInvoice - SQL Injection via Signup Check Username Parameter
CVE-2012-4237
TCExam < 11.3.008 - Authenticated SQL Injection via subject_module_id Parameter
CVE-2012-2601
Ipswitch WhatsUp Gold 15.02 - SQL Injection
CVE-2012-3435
Zabbix < 1.8.15 - SQL Injection via itemid Parameter
CVE-2012-4282
Trombinoscope 3.5 - SQL Injection via photo.php id Parameter
CVE-2012-2332
Serendipity < 1.6.1 - SQL Injection via serendipity[plugin_to_conf] Parameter
CVE-2012-4281
Travelon Express 6.2.2 - SQL Injection via Multiple Parameters
CVE-2012-4279
Free Realty 3.1-0.6 - SQL Injection via Agent Display or Admin Edit Parameters
CVE-2012-4265
Proman Xpress 5.0.1 - SQL Injection via category_edit.php cid Parameter
CVE-2012-4261
myCare2x - SQL Injection via lang Parameter
CVE-2012-4260
myCare2x - SQL Injection via Multiple Parameters
CVE-2012-4258
MYRE Real Estate Software 2012 Q2 - SQL Injection via link_idd or userid Parameter
CVE-2012-2325
MyBB < 1.6.7 - Authenticated SQL Injection via User Inline Moderation
CVE-2012-2324
MyBB < 1.6.7 - Authenticated SQL Injection via Admin Control Panel
CVE-2012-3471
Ushahidi Platform < 2.5 - SQL Injection via Incident ID Parameter
CVE-2012-3470
Ushahidi Platform < 2.5 - SQL Injection via Countries API
CVE-2012-3469
Ushahidi Platform < 2.5 - SQL Injection via Messages Admin or Location API
Details
Vulnerabilities 19,915
Exploit Likelihood High