CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-1615
Moodle 1.8.0-1.8.11 - SQL Injection via Wiki Module or Form Select Groups
CVE-2010-1605
NCT Jobs Portal Script - SQL Injection via anyword or cityname Parameter
CVE-2010-1604
NCT Jobs Portal Script - SQL Injection via admin_login.php User and Passwd Parameters
CVE-2010-1600
Media Mall Factory (com_mediamall) 1.0.4 - SQL Injection via Category Parameter
CVE-2010-1599
nkinfoweb 2.5 and 5.2.2.0 - SQL Injection via loadorder.php id_sp Parameter
CVE-2010-1595
OCS Inventory NG 1.02.1 - SQL Injection
CVE-2010-1588
Rocksalt International VP-ASP Shopping Cart <6.50 - SQL Injection
CVE-2010-1559
SermonSpeaker <3.2.1 - SQL Injection
CVE-2010-1538
phpRAINCHECK <1.0.1 - SQL Injection
CVE-2010-1529
Freestyle FAQs Lite - SQL Injection via faqid Parameter
CVE-2010-1499
MusicBox 3.3 - SQL Injection via Genre Artists ID Parameter
CVE-2010-1498
dl_stats < 2.0 - SQL Injection via id Parameter
CVE-2010-1496
Joomla! com_joltcard 1.2.1 - SQL Injection
CVE-2010-1493
com_awdwall < 1.5.4 - SQL Injection via cbuser Parameter
CVE-2010-1480
Joomla! com_rokmodule 1.1 - SQL Injection
CVE-2010-1479
Joomla! com_rokmodule 1.1 - SQL Injection
CVE-2010-1477
Joomla! com_sermonspeaker <3.2.1 - SQL Injection
CVE-2010-1468
com_mv_restaurantmenumanager < 1.5.2 - SQL Injection via mid Parameter
CVE-2010-1463
WebAsyst Shop-Script FREE - SQL Injection
CVE-2010-1426
MODx Evolution <1.0.3 - SQL Injection
CVE-2010-1372
HD FLV Player (com_hdflvplayer) 1.3 - SQL Injection via id Parameter
CVE-2010-1370
Pre Classified Listings ASP - SQL Injection
CVE-2010-1369
Pre Classified Listings ASP - SQL Injection
CVE-2010-1368
GameScript 3.0 - SQL Injection via index.php id Parameter
CVE-2010-1366
Uiga Fan Club 1.0 - SQL Injection via admin_name or admin_password Parameters
Details
Vulnerabilities 19,915
Exploit Likelihood High