CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,915 vulnerabilities with CWE-89
CVE-2009-3669
com_foobla_suggestions 1.5.11 - SQL Injection via idea_id Parameter
CVE-2009-3667
AdsDX 3.05 - SQL Injection via Username Parameter
CVE-2009-3665
Nullam Blog 0.1.2 - SQL Injection via i or v Parameter
CVE-2009-3661
Blueconstantmedia Com Djcatalog - SQL Injection
CVE-2009-3659
BS Counter 2.5.3 - SQL Injection via Page Parameter
CVE-2009-3645
JoomlaCache CB Resume Builder - SQL Injection via group_id Parameter
CVE-2009-3644
Soundset (com_soundset) 1.0 - SQL Injection via cat_id Parameter
CVE-2009-3642
FrontRange HEAT 8.01 - SQL Injection via Call Logging Username and Password Parameters
CVE-2009-3595
VS PANEL 7.5.5 - SQL Injection via Cat_ID Parameter
CVE-2009-3590
VS PANEL 7.3.6 - SQL Injection via Cat_ID Parameter
CVE-2009-3543
Phenotype CMS < 2.9 - SQL Injection via Login Name Parameter
CVE-2009-3533
Meeting Room Booking System < 1.4.2 - SQL Injection via report.php typematch Parameter
CVE-2009-3532
LogRover 2.3 and 2.3.3 - SQL Injection via Login Screen Parameters
CVE-2009-3531
Universe CMS 1.0.6 - SQL Injection via vnews.php id Parameter
CVE-2009-3529
RadScripts RadBids Gold 4 - SQL Injection via fid Parameter
CVE-2009-3528
MyMsg 1.0.3 - Authenticated SQL Injection via Profile.php uid Parameter
CVE-2009-3514
d.net CMS - SQL Injection via Page Parameter
CVE-2009-3510
linkspheric 0.74 Beta 6 - SQL Injection via listID Parameter
CVE-2009-3505
Vastal I-Tech MMORPG Zone - SQL Injection via view_news.php news_id Parameter
CVE-2009-3504
Alibaba Clone 3.0 - SQL Injection via offers_buy.php id Parameter
CVE-2009-3503
BPHolidayLettings 1.0 - SQL Injection via search.aspx rid or tid Parameter
CVE-2009-3502
BPowerHouse BPMusic 1.0 - SQL Injection via music_id Parameter
CVE-2009-3501
BPowerHouse BPStudents 1.0 - SQL Injection via students.php test parameter
CVE-2009-3500
BPowerHouse BPGames 1.0 - SQL Injection via cat_id or game_id Parameter
CVE-2009-3499
BPowerHouse BPLawyerCaseDocuments 1.0 - SQL Injection via employee.aspx cat Parameter
Details
Vulnerabilities 19,915
Exploit Likelihood High