CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2009-4621
JiangHu Inn < 1.1 - SQL Injection via id Parameter
CVE-2009-4620
Joomloc com_joomloc 1.0 - SQL Injection via id Parameter
CVE-2009-4619
Lucy Games (com_lucygames) 1.5.4 - SQL Injection via gameid Parameter
CVE-2009-4618
Tourism Script Bus Script - SQL Injection
CVE-2009-4617
Tourismscripts Tourism Script Accomodation Hotel Booking Portal Script - SQL Injection
CVE-2009-4615
MYRE Holiday Rental Manager - SQL Injection
CVE-2009-4613
NetArt Media Real Estate Portal 2.0 - SQL Injection
CVE-2009-4600
NetArt Media Real Estate Portal 2.0 - SQL Injection
CVE-2009-4599
JS Jobs (com_jsjobs) 1.0.5.6 - SQL Injection via md or oi Parameter
CVE-2009-4598
com_jphoto 1.0 - SQL Injection via id Parameter
CVE-2009-4597
PHP Inventory 1.2 - SQL Injection via User ID, Username, or Password Parameter
CVE-2009-4595
PHP Inventory 1.2 - Authenticated SQL Injection via sup_id Parameter
CVE-2009-4591
secureideas BASE < 1.4.4 - SQL Injection
CVE-2009-4583
Joomla DhForum Component - SQL Injection via id Parameter
CVE-2009-4582
XOOPS Dictionary module - SQL Injection via id Parameter
CVE-2009-4577
MDForum 2.x-2.07 - SQL Injection via c Parameter
CVE-2009-4576
cmstactics com_beeheard 1.x - SQL Injection via category_id Parameter
CVE-2009-4574
I-Escorts Directory Script - Country Escorts < PHP - SQL Injection
CVE-2009-4571
PhpShop 0.8.1 - SQL Injection via Multiple Parameters
CVE-2009-4569
Elkagroup Image Gallery - SQL Injection
CVE-2009-4566
Zenphoto 1.2.5 - SQL Injection via News Title Parameter
CVE-2009-4564
Zenphoto 1.2.5 - SQL Injection via Category Parameter
CVE-2009-4561
WebLeague 2.2.0 - SQL Injection via Username or Password Parameter
CVE-2009-4560
WebLeague 2.2.0 - SQL Injection via Profile Name Parameter
CVE-2009-4551
Miniweb 2.0 - SQL Injection via Survey Pro Campaign ID Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High