CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2012-1780
SocialCMS 1.0.5 - SQL Injection via Search Category Parameter
CVE-2012-1778
CreateVision CMS - SQL Injection via artykul_print.php id Parameter
CVE-2012-0293
Symantec Altiris WISE Package Studio <8.0MR1 - SQL Injection
CVE-2012-1557
Parallels Plesk Panel 7.x-8.6 MU#2, 9.x-9.5 MU#11, 10.0.x-MU#13, 10.1.x-MU#22, 10.2.x-MU#16, 10.3.x-MU#5 - SQL Injection
CVE-2012-0199
IBM Tivoli Provisioning Manager Express 4.1.1 SQL Injection via SOAP or EG2 File
CVE-2012-1210
Powie pFile 1.02 - SQL Injection via id Parameter
CVE-2012-0999
lepton < 1.1.4 - SQL Injection via group_id Parameter
CVE-2012-1294
CONTIMEX Impulsio CMS - SQL Injection via id Parameter
CVE-2012-1234
Advantech WebAccess 7.0 - Authenticated SQL Injection via Malformed URL
CVE-2012-0244
Advantech WebAccess < 7.0 - SQL Injection via Crafted String Input
CVE-2012-0234
Advantech WebAccess < 7.0 - SQL Injection via Malformed URL
CVE-2012-1225
Dolibarr < 3.2.0 - Authenticated SQL Injection via Memberslist or Rowid Parameter
CVE-2012-1218
freelancerkit 2.35 - SQL Injection in Notes and Tickets Components
CVE-2012-0994
zenphoto 1.4.2 - Authenticated SQL Injection via Manage Albums sortableList Parameter
CVE-2012-1077
TYPO3 bc_post2facebook <0.2.2 - SQL Injection
CVE-2012-1075
TYPO3 rtg_files <1.5.2 - SQL Injection
CVE-2012-1074
TYPO3 mm_whtppr <0.0.4 - SQL Injection
CVE-2012-1072
TYPO3 toi_category <0.6.0 - SQL Injection
CVE-2012-1071
Kitchen recipe <0.4.1 - SQL Injection
CVE-2012-1067
WP-RecentComments <2.0.7 - SQL Injection
CVE-2012-1063
ManageEngine Applications Manager <10.x - SQL Injection
CVE-2012-1061
GForge Advanced Server <6.0.1 - SQL Injection
CVE-2012-1029
Tube Ace 1.6 - SQL Injection via q Parameter
CVE-2012-1026
XRay CMS 1.1.1 - SQL Injection via Username or Password Parameter
CVE-2012-1022
4images 1.7.10 - SQL Injection via cat_parent_id Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High