CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2011-5200
DeDeCMS - SQL Injection via id Parameter
CVE-2011-5198
Neturf eCommerce Shopping Cart - SQL Injection via SearchFor Parameter
CVE-2011-5183
OrderSys <= 1.6.4 - SQL Injection via where_clause Parameter
CVE-2011-4960
SilverStripe 2.3.x < 2.3.12 and 2.4.x < 2.4.6 - SQL Injection
CVE-2011-4959
SilverStripe 2.3.x < 2.3.12 and 2.4.x < 2.4.6 - SQL Injection via MySQL Far East Character Encoding
CVE-2011-5175
Banana Dance < 1.5 - SQL Injection via search.php Category Parameter
CVE-2011-5169
SonicWall ViewPoint 6.0 SP2 - SQL Injection via scheduleID Parameter
CVE-2011-5168
banana_dance < 0.9 - SQL Injection via user.php id Parameter
CVE-2011-4448
WikkaWiki 1.3.1 and 1.3.2 - SQL Injection via default_comment_display Parameter
CVE-2011-4949
EGroupware < 1.8.001.20110421 and Enterprise Line < 11.1.20110711-1 - SQL Injection via id Parameter
CVE-2011-4946
e107 < 0.7.26 - SQL Injection via user_field Parameter
CVE-2011-5145
Open Business Management < 2.4.0 - Authenticated SQL Injection via Multiple Parameters
CVE-2011-5140
DiY-CMS blog module 1.0 - SQL Injection via Multiple Parameters
CVE-2011-5139
Pre Studio Business Cards Designer - SQL Injection via Page ID Parameter
CVE-2011-5137
tForum b0.915 - SQL Injection via TopicID, BoardID, or CatID Parameter
CVE-2011-5135
DoceboLMS < 4.0.4 - Authenticated SQL Injection via coursereportuiconfig Parameters
CVE-2011-5116
SetSeed CMS < 5.11.2 - SQL Injection via loggedInUser Cookie
CVE-2011-5113
Techfolio (com_techfolio) 1.0 - SQL Injection via catid Parameter
CVE-2011-5112
com_alameda < 1.0.0 - SQL Injection via Storeid Parameter
CVE-2011-5111
Kajian Website CMS Balitbang 3.x - SQL Injection via Hal Parameter
CVE-2011-5110
Blogs Manager < 1.101 - SQL Injection via SearchField Parameter
CVE-2011-5109
Freelancer Calendar < 1.01 - SQL Injection via SearchField Parameter
CVE-2011-5103
Alurian Prismotube PHP Video Script - SQL Injection via id Parameter
CVE-2011-5099
chillcreations mod_ccnewsletter 1.0.7-1.0.9 - SQL Injection via id Parameter
CVE-2011-4292
Moodle 2.0.0-2.0.2 - Authenticated Denial of Service via Crafted Comments
Details
Vulnerabilities 19,915
Exploit Likelihood High