CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2009-5102
ATCOM Netvolution 1.0 ASP - SQL Injection via bpe_nid Parameter
CVE-2009-5094
CMS Faethon 2.2.0 Ultimate - SQL Injection via info.php item Parameter
CVE-2009-5091
Vlinks 1.0.3 and 1.1.6 - SQL Injection via id Parameter
CVE-2009-5090
Bloggeruniverse Beta 2 - SQL Injection via editcomments.php id Parameter
CVE-2009-5088
IdeaCart 0.02 - SQL Injection via cID Parameter
CVE-2009-5003
e-soft24 Banner Exchange Script 1.0 - SQL Injection via click.php targetid Parameter
CVE-2009-4992
LM Starmail Paidmail 2.0 - SQL Injection via ID Parameter
CVE-2009-4985
Accessories Me PHP Affiliate Script 1.4 - SQL Injection via Go Parameter
CVE-2009-4982
Irokez CMS 0.7.1 - SQL Injection via PATH_INFO
CVE-2009-4979
Photokorn Gallery < 1.81 - SQL Injection via search.php Parameters
CVE-2009-4973
TotalCalendar 2.4 - SQL Injection via rss.php selectedCal Parameter
CVE-2009-4971
vjchat < 0.3.3 - SQL Injection
CVE-2009-4970
t3m_affiliate 0.5.0 - SQL Injection
CVE-2009-4969
TYPO3 SBanner 1.0.1 - SQL Injection
CVE-2009-4968
Event Registration (event_registr) < 1.0.0 - SQL Injection
CVE-2009-4967
Car < 0.1.0 - SQL Injection
CVE-2009-4966
AST ZipCodeSearch 0.5.4 - SQL Injection
CVE-2009-4965
AIRware Lexicon 0.0.1 - SQL Injection
CVE-2009-4959
stefan_koch/t3m < 0.2.4 - SQL Injection
CVE-2009-4958
EMO Breeder Manager - SQL Injection via video.php idd Parameter
CVE-2009-4955
th_ultracards < 0.5.1 - SQL Injection
CVE-2009-4954
sk_calendar < 0.3.4 - SQL Injection
CVE-2009-4950
A21glossary Advanced Output < 0.1.12 - SQL Injection
CVE-2009-4949
Store Locator extension < 1.2.8 for TYPO3 - SQL Injection
CVE-2009-4947
Q2 Solutions ConnX 4.0.20080606 - SQL Injection via txtEmail Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High