CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2011-1903
Proofpoint Messaging Security Gateway < 6.2.0.263 and Protection Server 5.5.3-6.2.0 - SQL Injection
CVE-2011-1610
Cisco Unified Communications Manager <8.5 - SQL Injection
CVE-2011-1609
Cisco Unified Communications Manager <6.1.5su2-8.5.1 - SQL Injection
CVE-2011-1522
Doctrine <1.2.4, <2.0.3 - SQL Injection
CVE-2011-1686
Best Practical Solutions RT <4.0.0rc - SQL Injection
CVE-2011-1722
WEC Discussion Forum <2.1.0 - SQL Injection
CVE-2011-1653
CA Total Defense UNC Server r12 - SQL Injection
CVE-2011-1667
Anzeigenmarkt 2011 - SQL Injection via q Parameter in list Action
CVE-2011-1663
Drupal Translation Mgmt <6.x-1.21 - SQL Injection
CVE-2011-1562
Ecava IntegraXor HMI <3.60 (Build 4032) - Auth Bypass
CVE-2011-1557
ICloudCenter ICJobSite <1.1 - SQL Injection
CVE-2011-1556
Andy's PHP Knowledgebase 0.95.4 - SQL Injection
CVE-2011-1555
Andy's PHP Knowledgebase <0.95.3 - SQL Injection
CVE-2011-1546
Andy's PHP Knowledgebase <0.95.3 - SQL Injection
CVE-2011-0432
PyWebDAV < 0.9.4.1 - SQL Injection via User or Password Argument
CVE-2011-1343
IBM Tivoli Netcool/OMNIbus <7.3.0.4 - SQL Injection
CVE-2011-0434
Domain Technologie Control < 0.32.9 - SQL Injection via cid Parameter
CVE-2011-1100
Pixelpost 1.7.3 - Authenticated SQL Injection via findfid, id, selectfcat, selectfmon, or selectftag Parameter
CVE-2011-1064
qibosoft Qi Bo CMS 7 - SQL Injection via aidDB Parameter
CVE-2011-1061
WSN Guest 1.24 - SQL Injection via Time Parameter
CVE-2011-1060
WSN Guest 1.24 - SQL Injection via wsnuser Cookie
CVE-2011-1055
lingxia_i.c.e_cms 1.0 - SQL Injection via session.user_id Parameter
CVE-2011-1048
MihanTools 1.33 - SQL Injection via product.php id Parameter
CVE-2011-1047
VastHTML Forum Server 1.6.1 and 1.6.5 - SQL Injection via Search Max Parameter
CVE-2011-0448
Ruby on Rails 3.0.x < 3.0.4 - SQL Injection via Non-Numeric Limit Argument
Details
Vulnerabilities 19,915
Exploit Likelihood High