CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2009-4796
glFusion <= 1.1.2 - SQL Injection via Order and Direction Parameters
CVE-2009-4795
Xlight FTP Server <3.2.1 - SQL Injection
CVE-2009-4794
Community CMS 0.5 - SQL Injection via article_id Parameter or Calendar Event Action
CVE-2009-4792
BandSite CMS 1.1.4 - SQL Injection via memid Parameter
CVE-2009-4791
Family Connections <1.8.2 - SQL Injection
CVE-2009-4785
Joomla! com_quicknews - SQL Injection
CVE-2009-4784
Joaktree com_joaktree 1.0 - SQL Injection via treeId Parameter
CVE-2009-4783
Theeta CMS - SQL Injection via Forum Start Parameter
CVE-2009-4751
Swinger Club Portal - Anzeiger <start.php - SQL Injection
CVE-2009-4749
PHP Live! 3.2.1-3.2.2 - SQL Injection via x Parameter
CVE-2009-4748
My Category Order <2.8 - SQL Injection
CVE-2009-4745
Dreamlevels DreamPoll 3.1 - SQL Injection
CVE-2009-4742
Docebo 3.6.0.3 - SQL Injection via FAQ Word Parameter
CVE-2009-4735
Allomani Audio & Video Library (Songs & Clips) <2.7.0 - SQL Injection
CVE-2009-4734
Allomani Movies Library <2.7.0 - SQL Injection
CVE-2009-4733
SimpleLoginSys 0.5 - SQL Injection via Username Parameter
CVE-2009-4732
TT Web Site Manager 0.5 - SQL Injection
CVE-2009-4731
Modeling Agency Content Management Script - SQL Injection
CVE-2009-4730
x10 Adult Media Script 1.7 - SQL Injection
CVE-2009-4728
Questions Answered <1.3 - SQL Injection
CVE-2009-4727
JungleScripts Ajax Short Url Script - SQL Injection
CVE-2009-4724
PaymentProcessorScript.net - SQL Injection
CVE-2009-4722
Limny 1.01 - SQL Injection via Username Parameter
CVE-2009-4721
Andrews-Web BannerAd 1.0 - SQL Injection
CVE-2009-4720
GnuDIP 2.1.1 - SQL Injection via Username Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High