CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2009-4380
Valarsoft Webmatic <3.0.3 - SQL Injection
CVE-2009-4375
AlienVault OSSIM <2.1.5.4 - SQL Injection
CVE-2009-4360
XOOPS 0.5 - Content Module - SQL Injection
CVE-2009-3703
WP-Forum < 2.4 - SQL Injection via Search Max Parameter
CVE-2009-4351
WSCreator 1.1 - SQL Injection via Email Parameter
CVE-2009-4350
Arctic Issue Tracker 2.1.1 - SQL Injection
CVE-2009-4342
TYPO3 jobexchange <0.0.3 - SQL Injection
CVE-2009-4341
TYPO3 no_indexed_search 0.2.0 - SQL Injection
CVE-2009-4339
TYPO3 mf_subscription 0.2.2 - SQL Injection
CVE-2009-4338
Flash SlideShow 0.2.2 - SQL Injection
CVE-2009-4337
TYPO3 pd_calendar <0.4.1 - SQL Injection
CVE-2009-4305
Moodle <1.8.11, <1.9.7 - SQL Injection
CVE-2009-4296
Drupal Taxonomy Timer <6.x-alpha1 - SQL Injection
CVE-2009-4238
TestLink - Authenticated SQL Injection via Test Case ID or logLevel Parameter
CVE-2009-4263
PTCPay GeN3 forum 1.3 - SQL Injection
CVE-2009-4256
AlefMentor 2.0 and 2.2 - SQL Injection via cont_id and courc_id Parameters
CVE-2009-4229
ActiveWebSoftwares Active Bids - SQL Injection
CVE-2009-4221
phpBazar < 2.1.1fix - SQL Injection via Classified.php catid Parameter
CVE-2009-4218
JiRo's Banner System eXperience - SQL Injection
CVE-2009-4217
Joomla! MusicGallery - SQL Injection
CVE-2009-4208
Open-school 1.0 - SQL Injection via os_news Module id Parameter
CVE-2009-4206
Million Dollar Text Links <1.0 - SQL Injection
CVE-2009-4204
Flashlight Free Edition - SQL Injection
CVE-2009-4203
Arab Portal 2.2 - SQL Injection via X-Forwarded-For or Client-IP Header
CVE-2009-4200
Joomla! Seminar <1.28 - SQL Injection
Details
Vulnerabilities 19,915
Exploit Likelihood High