CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-1365
Uiga Fan Club - SQL Injection via id Parameter in photos Action
CVE-2010-1364
Uiga Personal Portal - SQL Injection
CVE-2010-1363
com_j-projects - SQL Injection via Project Parameter
CVE-2010-1359
Direct URL module for xt:Commerce - SQL Injection via coID Parameter
CVE-2010-1350
com_jp_jobs < 1.4.1 - SQL Injection via id Parameter
CVE-2010-1346
Mini CMS RibaFS 1.0 - SQL Injection
CVE-2010-1344
Cookex Agency CKForms <1.3.3 - SQL Injection
CVE-2010-1343
SiteX 0.7.4 beta - SQL Injection via albumid Parameter
CVE-2010-1341
Systemsoftware Community Black Forum - SQL Injection
CVE-2010-1338
teamsite_hack_plugin < 3.0 - SQL Injection via ts_other.php userid Parameter
CVE-2010-1336
INVOhost 3.4 - SQL Injection via site.php id/newlanguage Parameters
CVE-2010-1331
Heartlogic HL-SiteManager - SQL Injection
CVE-2010-1301
Centreon 2.1.5 - SQL Injection via host_id Parameter
CVE-2010-1300
Yamamah (Dove Photo Album) 1.00 - SQL Injection
CVE-2010-0400
Mahara 1.0.4 - SQL Injection via Username Parameter
CVE-2010-1277
Zabbix < 1.8.2 - SQL Injection via API user.authenticate Method
CVE-2010-1271
smartplugs 1.3 - SQL Injection via showplugs.php Domain Parameter
CVE-2010-1270
Multi Auktions Komplett System 2 - SQL Injection
CVE-2010-1269
phpscripte24 Niedrig Gebote Pro Auktions System II - SQL Injection via auktion.php id_auk Parameter
CVE-2010-1265
Adam Corley dcsFlashGames - SQL Injection
CVE-2010-1134
TikiWiki CMS/Groupware <3.5 - SQL Injection
CVE-2010-1133
TikiWiki CMS/Groupware <4.2 - SQL Injection
CVE-2010-1109
phpMySport 1.4 - SQL Injection via Multiple Parameters
CVE-2010-1096
ScriptsFeed Dating Software - SQL Injection
CVE-2010-1094
DZ EROTIK Auktionshaus V4rgo - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High