CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-5017
Elite Gaming Ladders 3.0 - SQL Injection
CVE-2010-5016
Elite Gaming Ladders <3.5 - SQL Injection
CVE-2010-5015
2daybiz Network Community Script - SQL Injection
CVE-2010-5014
Elite Gaming Ladders 3.5 - SQL Injection
CVE-2010-5013
Mckenzie Creations VRM <3.5 - SQL Injection
CVE-2010-5012
DaLogin 2.2 and 2.2.5 - SQL Injection via new.php id Parameter
CVE-2010-5011
SchoolMation 2.3 - SQL Injection via Studentmain Session Parameter
CVE-2010-5009
UTStats Beta 4 and earlier - SQL Injection via pid Parameter in matchp Action
CVE-2010-5008
BrightSuite Groupware 5.4 - SQL Injection
CVE-2010-5006
EMO Realty Manager - SQL Injection via googlemap/index.php cat1 Parameter
CVE-2010-5004
2daybiz Polls Script - SQL Injection via searchvote.php category parameter
CVE-2010-5000
MCLogin System <1.3 - SQL Injection
CVE-2010-4997
OlyKit Swoopo Clone 2010 - SQL Injection
CVE-2010-5003
Joomla! AutarTimonial 1.0.8 - SQL Injection
CVE-2010-5001
Esoftpro Online Contact Manager 3.0 - SQL Injection
CVE-2010-4999
esoftpro Online Photo Pro 2.0 - SQL Injection
CVE-2010-4996
Esoftpro Online Guestbook Pro 5.1 - SQL Injection
CVE-2010-4995
NeoRecruit 1.6.4 - SQL Injection via Itemid Parameter
CVE-2010-4994
Joomla! Jobs Pro <1.6.4 - SQL Injection
CVE-2010-4993
Joomla! com_eventcal <1.6.4 - SQL Injection
CVE-2010-4992
Payments Plus 2.1.5 - SQL Injection
CVE-2010-4991
ninjaforge ninjamonials - SQL Injection via Itemid Parameter
CVE-2010-4990
com_addressbook - SQL Injection via Itemid Parameter
CVE-2010-4989
Ziggurat Farsi CMS - SQL Injection via main.asp grp Parameter
CVE-2010-4987
KMSoft Guestbook - SQL Injection via p Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High