CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2009-4940
ZeusCart 2.3 - SQL Injection via maincatid Parameter
CVE-2009-4938
com_jvideo 0.3.11c Beta and 0.3.x - SQL Injection via user_id Parameter
CVE-2009-4936
Small Pirate 2.1 - SQL Injection via id Parameter
CVE-2009-4935
Online Guestbook Pro - SQL Injection via display Parameter
CVE-2009-4933
Winterwebs Ezwebitor - SQL Injection
CVE-2009-4925
creasito e-commerce content manager 1.3.16 - SQL Injection via Username Parameter
CVE-2009-4892
webjump! - SQL Injection via id Parameter
CVE-2009-4891
CS-Cart 2.0.0 Beta 3 - SQL Injection via product_id Parameter
CVE-2009-4889
Book Panel - SQL Injection via bookid Parameter
CVE-2009-4884
phpCommunity 2 2.1.8 - SQL Injection via forum_id or topic_id Parameter
CVE-2009-4883
PHPRecipeBook 2.24 and 2.39 - SQL Injection via base_id or course_id Parameter
CVE-2009-4872
Logoshows BBS 2.0 - SQL Injection via Username and Password Fields
CVE-2009-4871
Logoshows BBS 2.0 - SQL Injection via globepersonnel_forum.asp forumid Parameter
CVE-2009-4870
PHPCityPortal - SQL Injection via Username or Password Parameter
CVE-2009-4865
I-Escorts Directory Script and Agency Script - SQL Injection via search_name or languages Parameter
CVE-2009-4862
Alwasel 1.5 - SQL Injection via id Parameter
CVE-2009-4860
Typing Pal 1.0 - SQL Injection via idTableProduit Parameter
CVE-2009-4855
TYPO3 4.0 - SQL Injection via showUid Parameter
CVE-2009-4838
Basic Analysis and Security Engine < 1.4.3 - SQL Injection
CVE-2009-4807
Graugon PHP Article Publisher 1.0 - SQL Injection via c or id Parameter
CVE-2009-4805
EZ-Blog Beta 1 - SQL Injection via StoryID or Kill Parameter
CVE-2009-4803
Accessibility Glossary < 0.4.10 - SQL Injection
CVE-2009-4802
Flat Manager < 1.9.16 - SQL Injection
CVE-2009-4798
Diskos CMS 6.x - SQL Injection via side.asp kat Parameter and Admin Login Fields
CVE-2009-4797
JobHut 1.2 - SQL Injection via browse.php pk Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High