CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,929 vulnerabilities with CWE-89
CVE-2009-3434
com_tupinambis 1.0 - SQL Injection via Proyecto Parameter
CVE-2009-3430
Allomani Mobile 2.5 - SQL Injection via Login Username Parameter
CVE-2009-3419
Miniweb Publisher Module 2.0 - SQL Injection via Historymonth Parameter
CVE-2009-3418
Plume CMS 1.2.3 - Authenticated SQL Injection via Manager Parameters
CVE-2009-3417
IDoBlog 1.1 build 30 - SQL Injection via Userid Parameter
CVE-2009-3361
PHP-IPNMonitor - SQL Injection via maincat_id Parameter
CVE-2009-3358
Tourism Scripts Adult Portal Escort Listing - SQL Injection via profile.php user_id Parameter
CVE-2009-3357
com_hbssearch - SQL Injection via h_id, id, or rid Parameters
CVE-2009-3356
Image voting 1.0 - SQL Injection via Show Parameter
CVE-2009-3349
Datavore Gyro 5.0 - SQL Injection via cid Parameter in Home Component
CVE-2009-3343
HotWeb Rentals - SQL Injection via PropId Parameter
CVE-2009-3342
AlphaUserPoints 1.5.2 - SQL Injection via Username2Points Parameter
CVE-2009-3337
serendipity_event_freetag < 3.09 - SQL Injection via Meta Keywords Parameter
CVE-2009-3336
PHP Pro Bid - SQL Injection via auction_id Parameter
CVE-2009-3335
TurtuShout 0.11 - SQL Injection via Name Field
CVE-2009-3334
Lhacky! Extensions Cave Joomla! Integrated Newsletters Component 0.2 - SQL Injection via newsid Parameter
CVE-2009-3332
JBudgetsMagic 0.3.2-0.4.0 - SQL Injection via bid Parameter
CVE-2009-3330
cP Creator 2.7.1 - SQL Injection via Support Ticket Parameter
CVE-2009-3327
WX-Guestbook 1.1.208 - SQL Injection via QUERY or USERNAME Parameter
CVE-2009-3326
CMScontrol 7.x - SQL Injection via id_menu Parameter
CVE-2009-3325
Focusdev Com Surveymanager - SQL Injection
CVE-2009-3321
SaphpLesson 4.3 - SQL Injection via CLIENT_IP HTTP Header
CVE-2009-3319
Dawaween 1.03 - SQL Injection via id Parameter in sec list Action
CVE-2009-3316
JReservation 1.0 and 1.5 - SQL Injection via pid Parameter
CVE-2009-3315
NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 - SQL Injection via Username Field
Details
Vulnerabilities 19,929
Exploit Likelihood High