CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-4799
Chipmunk Pwngame 1.0 - SQL Injection
CVE-2010-4797
Truworth Flex Timesheet - SQL Injection
CVE-2010-4796
phpyun 1.1.6 - SQL Injection via ProvinceID or E Parameter
CVE-2010-4795
JS Calendar (com_jscalendar) 1.5.1-1.5.4 - SQL Injection
CVE-2010-4793
Site2Nite Auto e-Manager - SQL Injection
CVE-2010-4791
MG User-Fotoalbum 1.0.1 - SQL Injection
CVE-2010-4784
PHP Web Scripts Easy Banner Free <2009.05.18 - SQL Injection
CVE-2010-4782
Softwebs Nepal Ananda Real Estate 3.4 - SQL Injection
CVE-2010-4780
Enano CMS <1.1.8-1.0.6pl3 - SQL Injection
CVE-2010-4776
PreProjects Pre Online Tests Generator Pro - SQL Injection
CVE-2010-4774
AuraCMS 1.62 - SQL Injection via pdf.php id Parameter
CVE-2010-4771
S-CMS 2.5 - SQL Injection via viewforum.php id Parameter
CVE-2010-4770
CommodityRentals DVD Rentals Script - SQL Injection
CVE-2010-4752
LightNEasy 3.2.1 - SQL Injection via Page Parameter
CVE-2010-4751
LightNEasy 3.2.1 - Authenticated SQL Injection via id Parameter
CVE-2010-4739
Maian Media Silver - Joomla! < SQL Injection
CVE-2010-4738
Rae Media INC Real Estate <3.0 - SQL Injection
CVE-2010-4737
HotWebScripts HotWeb Rentals - SQL Injection
CVE-2010-4736
GateSoft DocuSafe <4.1.2 - SQL Injection
CVE-2010-4735
Ecommercemax Solutions DGS <1.5 - SQL Injection
CVE-2010-3929
MODx Evolution < 1.0.4 - SQL Injection via AjaxSearch
CVE-2010-4721
Immo Makler - SQL Injection via News.php ID Parameter
CVE-2010-4720
JExtensions JE Auto (com_jeauto) < 1.0 - SQL Injection via View Item Page
CVE-2010-4703
HotWebScripts HotWeb Rentals - SQL Injection
CVE-2010-4702
com_jradio < 1.5.0 - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High