CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2010-0454
Publique! 2.3 - SQL Injection via sid Parameter
CVE-2010-0139
Cisco Unified MeetingPlace 7 < 7.0(2.3) hotfix 5F and 6 < 6.0.639.2 - SQL Injection
CVE-2010-0381
phpmyspace 8.0-8.10 - SQL Injection via gid Parameter
CVE-2010-0377
phpmyspace 8.0 and 8.10 - SQL Injection via gid Parameter
CVE-2010-0375
JCE-Tech PHP Calendars - SQL Injection via cat Parameter
CVE-2010-0373
Joomla! com_libros - SQL Injection via id Parameter
CVE-2010-0372
com_articlemanager - SQL Injection via artid Parameter
CVE-2010-0344
zak_store_management < 1.0.0 - SQL Injection
CVE-2010-0343
pb_clanlist 0.0.1 - SQL Injection
CVE-2010-0342
TYPO3 job_reports < 0.1.0 - SQL Injection
CVE-2010-0341
Typo3 BB Simplejobs < 0.1.0 - SQL Injection
CVE-2010-0340
Typo3 Mjseventpro < 0.2.1 - SQL Injection
CVE-2010-0339
vm19_userlinks < 0.1.1 - SQL Injection
CVE-2010-0338
TT_Products editor (ttpedit) <= 0.0.2 - SQL Injection
CVE-2010-0337
dl3_tt_news_alerts < 0.2.0 - SQL Injection
CVE-2010-0334
Vote rank for news (vote_for_tt_news) <= 1.0.1 - SQL Injection
CVE-2010-0333
mg_help < 1.1.6 - SQL Injection
CVE-2010-0332
TV21 Talkshow < 1.0.1 - SQL Injection
CVE-2010-0330
jf_easymaps < 1.0.2 - SQL Injection
CVE-2010-0329
powermail < 1.5.1 - SQL Injection via SQL Selection Field
CVE-2010-0324
Customer Reference List (ref_list) < 1.0.1 - SQL Injection
CVE-2010-0322
mk_anydropdownmenu < 0.3.28 - SQL Injection
CVE-2010-0158
JoomlaBamboo JB Simpla Admin Template - SQL Injection via id Parameter
CVE-2009-4899 CRITICAL
pixelpost 1.7.1 - SQL Injection
CVSS 9.8
CVE-2009-5026
MySQL 5.0.x < 5.0.93 and 5.1.x < 5.1.50 - SQL Injection via Executable Comment Feature
Details
Vulnerabilities 19,915
Exploit Likelihood High