CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,929 vulnerabilities with CWE-89
CVE-2009-2640
Interlogy Profile Manager Basic - SQL Injection
CVE-2009-2639
MRCGIGUY The Ticket System 2.0 - SQL Injection
CVE-2009-2638
konze com_akobook 2.3 - SQL Injection via gbid Parameter
CVE-2009-2619
DataCheck Solutions V-SpacePal - SQL Injection
CVE-2009-2618
MDPro 1.083.x - SQL Injection via PollID Parameter
CVE-2009-2616
DataCheck Solutions SitePal <1 - SQL Injection
CVE-2009-2614
DataCheck Solutions LinkPal <1 - SQL Injection
CVE-2009-2612
ProSMDR - SQL Injection via login.aspx txtUser Parameter
CVE-2009-2609
amoCourse (com_amocourse) - SQL Injection via catid Parameter
CVE-2009-2608
PHP Address Book 4.0.x - SQL Injection
CVE-2009-2607
com_pinboard - SQL Injection via Task Parameter
CVE-2009-2605
Traidnt Up 2.0 - SQL Injection via trupuser and truppassword Cookies
CVE-2009-2604
Zen Help Desk 2.1 - SQL Injection via Userid or Password Parameter
CVE-2009-2603
Escon SupportPortal Pro 3.0 - SQL Injection
CVE-2009-2601
Joomlaequipment <2.0.4 - SQL Injection
CVE-2009-2599
RadCLASSIFIEDS Gold 2.0 - SQL Injection
CVE-2009-2598
Online Grades & Attendance <3.2.6 - SQL Injection
CVE-2009-2593
Censura 1.16.04 - SQL Injection via itemid Parameter
CVE-2009-2592
PHPJunkYard GBook 1.6 - SQL Injection
CVE-2009-2591
runcms myannonces - SQL Injection via lid Parameter
CVE-2009-2590
Hutscripts PHP Website Script - SQL Injection
CVE-2009-2585
Mlffat 2.2 - SQL Injection via Member Cookie in Edit Profile Action
CVE-2009-2573
MiniTwitter 0.2 beta - Authenticated SQL Injection via User Parameter
CVE-2009-2567
Joomla! com_aclassf <5.6.2 - SQL Injection
CVE-2009-2554
Joomla! Jobline <1.3.1 - SQL Injection
Details
Vulnerabilities 19,929
Exploit Likelihood High