CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-5058
CMS Ariadna 1.1 - SQL Injection via detResolucion.php res_id Parameter
CVE-2010-5057
CMS Ariadna 1.1 - SQL Injection via detResolucion.php tipodoc_id Parameter
CVE-2010-5056
GBU Facebook (com_gbufacebook) 1.0.5 - SQL Injection via face_id Parameter
CVE-2010-5055
Almnzm 2.1 - SQL Injection via id Parameter
CVE-2010-5053
com_xobbix 1.0.1 - SQL Injection via prodid Parameter
CVE-2010-5049
Zabbix < 1.8.1 - SQL Injection via events.php nav_time Parameter
CVE-2010-5047
V-EVA Press Release Script - SQL Injection
CVE-2010-5044
Joomla! com_searchlog 3.1.0 - SQL Injection
CVE-2010-5043
DJ-ArtGallery 0.9.1 - SQL Injection
CVE-2010-5041
NP_Gallery plugin 0.94 - SQL Injection via id Parameter
CVE-2010-5039
ScriptsFeed Recipes Listing Portal 1.0 - SQL Injection
CVE-2010-5037
SenseSites CommonSense CMS - SQL Injection
CVE-2010-5036
iScripts eSwap 2.0 - SQL Injection via addsale.php type Parameter
CVE-2010-5034
iScripts EasyBiller 1.1 - SQL Injection
CVE-2010-5033
Fusebox 5.5.1 - SQL Injection via CatDisplay Parameter
CVE-2010-5032
Joomla! com_bfquiztrial <1.3.1 - SQL Injection
CVE-2010-5029
ecomat_cms 5.0 - SQL Injection via Index.php Show Parameter
CVE-2010-5028
Joomla! com_jejob 1.0 - SQL Injection
CVE-2010-5026
Science Fair In A Box <2.0.6, 2.2.0 - SQL Injection
CVE-2010-5024
CuteSITE CMS <1.5.0 - SQL Injection
CVE-2010-5023
Digital Interchange Calendar <5.8.5 - SQL Injection
CVE-2010-5022
JExtensions JE Story Submit (com_jesubmit) 1.4 - SQL Injection via View Parameter
CVE-2010-5021
Digital Interchange Document Library <5.8.5 - SQL Injection
CVE-2010-5020
NetArt Media iBoutique 4.0 - SQL Injection
CVE-2010-5019
2daybiz Online Classified Script - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High