CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2011-4826
AutoSec Tools V-CMS 1.0 - SQL Injection via User Parameter
CVE-2011-4824
Cacti < 0.8.7h - SQL Injection via login_username Parameter
CVE-2011-4823
Extensionsforjoomla Com Vikrealestate - SQL Injection
CVE-2011-4811
BestShopPro - SQL Injection via pokaz_podkat.php str Parameter
CVE-2011-4808
HM Community < 1.0 - SQL Injection via id Parameter
CVE-2011-4803
WPTouch - SQL Injection via id Parameter
CVE-2011-4802
Dolibarr < 3.1.0 - Authenticated SQL Injection via Multiple Parameters
CVE-2011-4801
Authenex Strong Authentication System Server 3.1.0.2-3.1.0.3 SQL Injection via Username Parameter
CVE-2011-4349
colord < 0.1.15 - SQL Injection via Device ID, Property, or Profile ID
CVE-2011-4710
Pixie CMS 1.01-1.04 - SQL Injection via pixie_user Parameter or Referer Header
CVE-2011-2917
Mambo < 4.6.5 - SQL Injection via zorder Parameter
CVE-2011-4674
Zabbix 1.8.3-1.8.4 - SQL Injection via only_hostid Parameter
CVE-2011-4673
Jetpack - SQL Injection via id Parameter
CVE-2011-4672
Valid tiny-erp < 1.6 - SQL Injection via SearchField Parameter
CVE-2011-4671
AdRotate < 3.6.8 - SQL Injection via Track Parameter
CVE-2011-4669
WordPress Users < 1.3 - SQL Injection via uid Parameter
CVE-2011-4542
Hastymail2 2.1.1 - Remote Code Execution via rs or rsargs[] Parameter
CVE-2011-4571
Estate Agent (com_estateagent) - SQL Injection via id Parameter
CVE-2011-4570
Time Returns (com_timereturns) 2.0 - SQL Injection via id Parameter
CVE-2011-4569
Userbar plugin 2.2 for MyBB Forum - SQL Injection via image2 Parameter
CVE-2011-4559
vtiger CRM < 5.2.1 - SQL Injection via Calendar Module onlyforuser Parameter
CVE-2011-4066
Gnuboard < 4.33.02 - SQL Injection via PATH_INFO
CVE-2011-3989
DBD::mysqlPP <= 0.04 - SQL Injection
CVE-2011-4215
OneOrZero AIMS 2.7.0 - SQL Injection
CVE-2011-1915
Infor eClient 7.3.2.3 and Enspire Distribution Management Solution 7.3.2.7 - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High