CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-4400
DynPG CMS 4.2.0 - SQL Injection via giveRights_UserId Parameter
CVE-2010-4280
Pandora FMS < 3.1 - Authenticated SQL Injection via id_group or group_id Parameter
CVE-2010-3267
BugTracker.NET <3.4.5 - SQL Injection
CVE-2010-4365
Harmistechnology Com Jeajaxeventcalendar - SQL Injection
CVE-2010-4363
MRCGIGUY FreeTicket 1.0.0 - SQL Injection via contact.php id or email Parameter
CVE-2010-4362
MicroNetsoft RV Dealer Website - SQL Injection via selStock or orderBy Parameter
CVE-2010-4360
jurpopage 0.2.0 - SQL Injection via note or pg Parameter
CVE-2010-4359
jurpopage 0.2.0 - SQL Injection via Category Parameter
CVE-2010-4357
SiteEngine 7.1 - SQL Injection via Module Parameter
CVE-2010-4356
Site2Nite Big Truck Broker - SQL Injection via txtSiteId Parameter
CVE-2010-4298
Free Simple Software 1.0 - SQL Injection via downloads_id Parameter
CVE-2010-4273
DescargarVista ACC IMoveis 1.1 - SQL Injection via id Parameter
CVE-2010-4272
Pulse Infotech Sponsor Wall (com_sponsorwall) 1.1 - SQL Injection via catid Parameter
CVE-2010-4271
ImpressCMS < 1.2.3 - SQL Injection
CVE-2010-4269
Collabtive 0.65 - SQL Injection via managechat.php chatstart[USERTOID] Cookie
CVE-2010-4268
Pulse Infotech Flip Wall (com_flipwall) 1.1 - SQL Injection via catid Parameter
CVE-2010-2635
IBM WebSphere Commerce <6.0.0.10 - SQL Injection
CVE-2010-4186
OnlineTechTools OWOS Professional Edition 2.10 - SQL Injection via Password Parameter
CVE-2010-4185
Energine < 2.3.8 - SQL Injection via NRGNSID Cookie
CVE-2010-4152
4site CMS < 2.6 - SQL Injection via Catalog Index cat Parameter
CVE-2010-4151
DeluxeBB 1.3 - SQL Injection via xthedateformat Parameter
CVE-2010-4006
WSN Links < 5.0.81, < 5.1.51, < 6.0.1 SQL Injection via search.php
CVE-2010-4147
Avactis Shopping Cart < 1.9.1 - SQL Injection via User-Agent Header
CVE-2010-4144
Kisisel Radyo Script - SQL Injection via Id Parameter
CVE-2010-4143
phpcheckz 1.1.0 - SQL Injection via chart.php id Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High