CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-4986
Simple Document Management System - SQL Injection
CVE-2010-4984
My Kazaam Notes Management System - SQL Injection
CVE-2010-4983
iScripts CyberMatch 1.0 - SQL Injection
CVE-2010-4982
My Kazaam Address & Contact Organizer - SQL Injection
CVE-2010-4981
YourFreeWorld Banner Management - SQL Injection
CVE-2010-4980
iScripts ReserveLogic 1.0 - SQL Injection
CVE-2010-4979
CANDID - SQL Injection via image_id Parameter
CVE-2010-4977
Joomla! com_canteen 1.0 - SQL Injection
CVE-2010-4975
Techjoomla com_socialads - SQL Injection via Ads Description Field
CVE-2010-4974
BrotherScripts Auto Dealer - SQL Injection via info.php id Parameter
CVE-2010-4972
YPNinc JokeScript - SQL Injection via ypncat_id Parameter
CVE-2010-4970
Wiki Web Help 0.28 - SQL Injection via id Parameter
CVE-2010-4969
BrotherScripts Business Directory - SQL Injection via articlesdetails.php id Parameter
CVE-2010-4968
Joomla! com_wmtpic <1.0 - SQL Injection
CVE-2010-4967
ATCOM Netvolution 2.5.6 - SQL Injection
CVE-2010-4963
Hulihan BXR 0.6.8 - SQL Injection via order_by Parameter
CVE-2010-4961
TYPO3 webrtc <1.1.4 - SQL Injection
CVE-2010-4959
Pre Projects Pre Podcast Portal - SQL Injection
CVE-2010-4958
Prado Portal 1.2.0 - SQL Injection via Page Parameter
CVE-2010-4957
TYPO3 ke_questionnaire <2.2.3 - SQL Injection
CVE-2010-4955
APBoard Developers APBoard < 2.1.0 - SQL Injection via id Parameter
CVE-2010-4954
xt:Commerce Gambio 2008 - SQL Injection
CVE-2010-4952
TYPO3 festat <0.2.4 - SQL Injection
CVE-2010-4950
joachim_ruhs/event < 0.3.4 - SQL Injection
CVE-2010-4946
ALLPC 2.5 - SQL Injection via products_id Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High