CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,929 vulnerabilities with CWE-89
CVE-2009-3314
Elite Gaming Ladders 3.2 - SQL Injection via Platform Parameter
CVE-2009-3313
FMyClone 2.3 - SQL Injection via comp Parameter
CVE-2009-3310
Zainu 1.0 - SQL Injection via AlbumSongs Album ID Parameter
CVE-2009-3309
CF ShopKart 5.4 beta - SQL Injection via index.cfm itemid Parameter
CVE-2009-3308
FanUpdate 2.2.1 - SQL Injection via show-cat.php listingid Parameter
CVE-2009-3259
RASH Quote Management System 1.2.2 - SQL Injection via Search Parameter or User_Name Cookie
CVE-2009-3255
thomas_cuchta/rash < 1.2.2 - SQL Injection via User Parameter
CVE-2009-3252
Dave Robinson Rockbandcms - SQL Injection
CVE-2009-3246
MyBuxScript PTC-BUX - SQL Injection via spnews.php id Parameter
CVE-2009-3226
Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds - SQL Injection via replid Parameter
CVE-2009-3224
Super Mod System - SQL Injection via s Parameter
CVE-2009-3223
inout_adserver - Authenticated SQL Injection via id Parameter
CVE-2009-3218
AR Web Content Manager 2.1 - SQL Injection via Username Parameter
CVE-2009-3217
iWiccle 1.01 - SQL Injection via member_id Parameter
CVE-2009-3215
ixxo_cart < 3.9.6.1 - SQL Injection via Parent Parameter
CVE-2009-3212
VivaPrograms Infinity Script 2.x.x - SQL Injection via Username Field
CVE-2009-3209
PHP eMail Manager 3.3.0 - SQL Injection via ID Parameter
CVE-2009-3208
phpfreeBB 1.0 - SQL Injection via id Parameter or year Parameter
CVE-2009-3205
CBAuthority - SQL Injection via id Parameter in view_product Action
CVE-2009-3203
AJ Auction Pro OOPD 2.x - SQL Injection via store.php id Parameter
CVE-2009-3165
Bugzilla 2.23.4-3.0.8, 3.1.1-3.2.4, 3.3.1-3.4.1 - SQL Injection via Bug.create WebService Function
CVE-2009-3125
Bugzilla 3.3.2-3.4.1 and 3.5 - SQL Injection via Bug.search WebService Function
CVE-2009-3193
uwix com_digifolio 1.52 - SQL Injection via id Parameter
CVE-2009-3190
PAD Site Scripts 3.6 - SQL Injection via Search or RSS Category Parameter
CVE-2009-3185
Crazy Star plugin 2.0 for Discuz! - Authenticated SQL Injection via fmid Parameter
Details
Vulnerabilities 19,929
Exploit Likelihood High