CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-4857
CAG CMS 0.2 Beta - SQL Injection via click.php itemid Parameter
CVE-2010-4856
xWeblog 2.2 - SQL Injection via arsiv.asp tarih Parameter
CVE-2010-4855
xWeblog 2.2 - SQL Injection via makale_id Parameter
CVE-2010-4854
Zuitu 1.6 - SQL Injection via id Parameter in consume Action
CVE-2010-4853
chillcreations com_ccinvoices - SQL Injection via id Parameter
CVE-2010-4851
Eclime 1.1.2b - SQL Injection via ref poll_id or country Parameter
CVE-2010-4849
Alibaba Clone B2B 3.4 - SQL Injection
CVE-2010-4847
MH Products MHP Downloadshop - SQL Injection
CVE-2010-4846
MH Products Pay Pal Shop Digital - SQL Injection
CVE-2010-4845
MH Products Projekt Shop - SQL Injection
CVE-2010-4844
MH Products Easy Online Shop - SQL Injection
CVE-2010-4843
PHP Web Scripts Ad Manager Pro 3.0 - SQL Injection
CVE-2010-4842
MHP DownloadScript <2.2 - SQL Injection
CVE-2010-4839
WordPress Event Registration <5.32 - SQL Injection
CVE-2010-4838
com_jsupport 1.5.6 - Authenticated SQL Injection via Alpha Parameter
CVE-2010-4834
OneOrZero AIMS 2.6.0-2.7.0 - SQL Injection
CVE-2010-4830
Techno Dreams Job Career Package 3.0 - SQL Injection
CVE-2010-4829
Techno Dreams (T-Dreams) Cars Ads Package 2.0 - SQL Injection
CVE-2010-4826
Snitz Forums 2000 3.4.07 - SQL Injection
CVE-2010-4814
Best Soft Inc. Advance Hotel Booking System 1.0 - SQL Injection
CVE-2010-4812
6kbbs 8.0 build 20100901 - SQL Injection via tids[] or msgids[] Parameters
CVE-2010-4809
DBSite 1.0 - SQL Injection via ID Parameter
CVE-2010-4808
Webmatic - SQL Injection via Index.php p Parameter
CVE-2010-4284
Samsung Data Management Server < 1.4.3 - SQL Injection via Authentication Form
CVE-2010-4800
baconmap 1.0 - SQL Injection via doadd.php type Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High