CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2011-3615
Simple Machines Forum <1.1.15, <2.0.1 - SQL Injection
CVE-2011-4026
NexusPHP 1.5 - SQL Injection via Thanks.php ID Parameter
CVE-2011-3988
EC-CUBE 2.11.0-2.11.2 - SQL Injection in SC_Query.php
CVE-2011-3340
ATCOM Netvolution 2.5.8 - SQL Injection via Referer HTTP Header
CVE-2011-0553
Symantec IM Manager < 8.4.18 - SQL Injection
CVE-2011-3688
Sonexis ConferenceManager 9.3.14.0 - SQL Injection
CVE-2011-1913
Mercator SENTINEL 2.0 - SQL Injection
CVE-2011-3394
MYRE Real Estate Software - SQL Injection
CVE-2011-2930
Ruby on Rails < 2.3.13, 3.0.x < 3.0.10, 3.1.x < 3.1.0.rc5 - SQL Injection via Crafted Column Name
CVE-2011-1342
Aimluck Aipo <5.1.1 - SQL Injection
CVE-2011-3130
WordPress 3.1-3.1.2 and 3.2 Beta 1 - SQL Injection in Taxonomy Query
CVE-2011-2703
MapServer < 4.10.7, 5.x < 5.6.7, 6.x < 6.0.1 - SQL Injection via OGC Filter Encoding or WMS Time Support
CVE-2011-2403
HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, 9.10 - Authenticated SQL Injection
CVE-2011-2546
Cisco SA500 Series < 2.1.19 - SQL Injection
CVE-2011-2688
mod_authnz_external < 3.2.5 - SQL Injection via User Field
CVE-2011-2467
Likewise Open 5.4-6.1 - Local SQL Injection
CVE-2011-2751
Parodia < 6.8 - SQL Injection
CVE-2011-0549
Symantec Web Gateway 4.5.x - SQL Injection via Username Parameter
CVE-2011-2181
A Really Simple Chat 3.3-rc2 - SQL Injection via arsc_user, arsc_layout_id, or arsc_room Parameter
CVE-2011-1480
Francisco Burzi PHP-Nuke <8.0 - SQL Injection
CVE-2011-1328
RADVISION iVIEW Suite <7.5 - SQL Injection
CVE-2011-2149
SmarterStats 6.0 - SQL Injection via Multiple Parameters and Headers
CVE-2011-0960
Cisco Unified Operations Manager < 8.6 - SQL Injection via CCMs or ccm Parameter
CVE-2011-2141
IBM Datacap Taskmaster Capture <8.0.1 - SQL Injection
CVE-2011-2080
MediaCAST < 8 - SQL Injection via CP_ENLARGESTYLE Cookie or authenticate_ad_setup_finished.cfm
Details
Vulnerabilities 19,915
Exploit Likelihood High