CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2011-4460
Bestpractical RT - SQL Injection
CVE-2011-5091
grboard 1.8.6.5 - SQL Injection via tableType, blindTarget, delTargets[0], or isReported Parameter
CVE-2011-1390
IBM Rational ClearQuest <8.0.0.2 - SQL Injection
CVE-2011-4816
IBM Maximo Asset Management 6.2, 7.1, 7.5 - Authenticated SQL Injection in KPI Component
CVE-2011-4487
Cisco Unified Communications Manager SQL Injection via SCCP Registration
CVE-2011-4521
Advantech WebAccess < 7.0 - SQL Injection via Crafted String Input
CVE-2011-4113
Drupal Views <6.x-2.13 - SQL Injection
CVE-2011-5076
HDWiki 5.0, 5.1 - SQL Injection via PATH_INFO to index.php
CVE-2011-5072
Support Incident Tracker < 3.65 - SQL Injection via Multiple Parameters
CVE-2011-5071
Support Incident Tracker < 3.64 - SQL Injection via Multiple Parameters
CVE-2011-3831
Support Incident Tracker <3.65 - SQL Injection
CVE-2011-5050
Cyberoam Unified Threat Management < 10.01.2 - Authenticated SQL Injection via tableid Parameter
CVE-2011-4921
e107 0.7.26 - SQL Injection via Username Parameter
CVE-2011-5039
Infoproject Biznis Heroj - SQL Injection via login.php or widget.dokumenti_lista.php
CVE-2011-5038
hitAppoint 4.5.17 - SQL Injection via Username Parameter
CVE-2011-5031
capexweb 1.1 - SQL Injection via dfuserid and dfpassword Parameters
CVE-2011-5022
Pligg CMS 1.1.2 - SQL Injection via Status Parameter
CVE-2011-3838
Wuzly 2.0 - SQL Injection via Multiple Parameters
CVE-2011-4847
Parallels Plesk Panel 10.4.4_build20111103.18 - SQL Injection via Certificateslist Cookie
CVE-2011-4763
Parallels Plesk Small Business Panel 10.2.0 - SQL Injection via Site Editor Input
CVE-2011-4753
Parallels Plesk Small Business Panel 10.2.0 - SQL Injection via PHP Script Input
CVE-2011-4734
Parallels Plesk Panel 10.2.0 build 20110407.20 - SQL Injection via PHP Script Input
CVE-2011-4725
Parallels Plesk Panel 10.2.0_build1011110331.18 - SQL Injection via PHP Script Input
CVE-2011-4833
SugarCRM 6.1-6.1.6 6.2-6.2.3 6.3-6.3.0RC2 6.4-6.4.0beta - SQL Injection via Leads Module Parameters
CVE-2011-4829
Barter Sites com_listing 1.3 - SQL Injection via category_id Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High