CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,930 vulnerabilities with CWE-89
CVE-2009-2341
Opial 1.0 - SQL Injection via albumid Parameter
CVE-2009-2340
Opial 1.0 - SQL Injection via txtUserName Parameter
CVE-2009-2339
Rentventory - SQL Injection via Product Parameter
CVE-2009-2337
w3b|cms Gaestebuch Guestbook Module 3.0.0 - SQL Injection
CVE-2009-2326
KerviNet Forum <1.1 - SQL Injection
CVE-2009-2311
rGallery plugin 1.2.3 for WoltLab Burning Board - SQL Injection via userID Parameter
CVE-2009-2310
Extensible-BioLawCom CMS <0.2.0 - SQL Injection
CVE-2009-2309
Codice CMS 2 - SQL Injection via Tag Parameter
CVE-2009-2308
Affiliation module for PunBB <= 1.1.0 - SQL Injection via in or out Parameter
CVE-2009-2307
maxdev cwguestbook < 2.1 - SQL Injection via rid Parameter
CVE-2009-2290
Boy Scout Advancement <0.3 - SQL Injection
CVE-2009-2276
Vote For Us Extension < 1.0.1 - SQL Injection via 'out' Parameter
CVE-2009-2269
Empire CMS 5.1 - SQL Injection via bid Parameter
CVE-2009-2254
Zen Cart <1.3.8a-1.3.8 - SQL Injection
CVE-2009-2243
ASP Inline Corporate Calendar - SQL Injection
CVE-2009-2242
ASP Inline Corporate Calendar - SQL Injection
CVE-2009-2239
Joomla com_casinobase, com_casino_blackjack, com_casino_videopoker 0.3.1 - SQL Injection via Itemid Parameter
CVE-2009-2236
Your Article Directory - SQL Injection
CVE-2009-2235
Your Articles Directory - SQL Injection
CVE-2009-2234
VICIDIAL Call Center Suite <2.0.5-173 - SQL Injection
CVE-2009-2232
Softbiz Banner Ad Mgt Script - SQL Injection
CVE-2009-2230
MyBB <1.4.7 - SQL Injection
CVE-2009-2209
RS-CMS 2.1 - SQL Injection via key Parameter
CVE-2009-2179
phpDatingClub 3.7 - SQL Injection via search.php sform[day] Parameter
CVE-2009-2167
EgyPlus 7ammel < 1.0.1 - SQL Injection via Username or Password Parameter
Details
Vulnerabilities 19,930
Exploit Likelihood High