CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,929 vulnerabilities with CWE-89
CVE-2009-3184
E-Gold Game Series Pirates of The Caribbean - SQL Injection via x and y Parameters
CVE-2009-3175
Model Agency Manager PRO - SQL Injection via user_id or id Parameter
CVE-2009-3154
Almond Classifieds (com_aclassf) 7.5 - SQL Injection via replid Parameter
CVE-2009-3150
Multi Website 1.5 - SQL Injection via Browse Parameter
CVE-2009-3148
PortalXP Teacher Edition 1.2 - SQL Injection via id or assignment_id Parameter
CVE-2009-3119
Download System mSF for PHP-Fusion - SQL Injection via screen.php view_id Parameter
CVE-2009-3118
Danneo CMS < 0.5.2 - SQL Injection via comtext Parameter
CVE-2009-3117
Snow Hall Silurus System 1.0 - SQL Injection via ID Parameter
CVE-2009-3116
Uiga Church Portal - SQL Injection via Year Parameter in Calendar Action
CVE-2009-3082
Snow Hall Silurus System 1.0 - SQL Injection via ID Parameter
CVE-2009-3081
Uiga Church Portal - SQL Injection via Month Parameter in Calendar Action
CVE-2009-3063
com_gameserver 1.0 for Joomla! - SQL Injection via id Parameter
CVE-2009-3062
Phplivesupport. Phplive! - SQL Injection
CVE-2009-3061
Alqatari Q R Script 1.0 - SQL Injection via lesson.php id Parameter
CVE-2009-3059
Allpublication Jboard < 2.0 - SQL Injection
CVE-2009-3054
Artetics Art Portal (com_artportal) 1.0 - SQL Injection via Portalid Parameter
CVE-2009-3052
Prime Quick Style < 1.2.3 - Authenticated SQL Injection via prime_quick_style Parameter
CVE-2009-3042
ocs_inventory_ng 1.02.1 - SQL Injection via machine.php systemid Parameter
CVE-2009-3040
OCS Inventory NG 1.02 - SQL Injection via download.php Parameters or group_show.php SYSTEMID
CVE-2009-2978
SugarCRM < 4.5.1o, < 5.0.0k, <= 5.2.0g - SQL Injection
CVE-2009-2933
Piwigo < 2.0.3 - SQL Injection via items_number Parameter
CVE-2009-2929
TGS Content Management 0.x - SQL Injection via Multiple Parameters
CVE-2009-2927
DigitalSpinners DS CMS 1.0 - SQL Injection via DetailFile.php nFileId Parameter
CVE-2009-2926
PHP Competition System BETA 0.84 - SQL Injection via Day or Pageno Parameter
CVE-2009-2924
Videos Broadcast Yourself 2 - SQL Injection via UploadID Parameter
Details
Vulnerabilities 19,929
Exploit Likelihood High