CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,930 vulnerabilities with CWE-89
CVE-2009-1818
MaxCMS 2.0 - SQL Injection via m_username Cookie
CVE-2009-1816
My Game Script 2.0 - SQL Injection via User Parameter
CVE-2009-1814
PHPenpals < 1.1 - SQL Injection via mail.php ID Parameter
CVE-2009-1813
Submitterscript - SQL Injection
CVE-2009-1812
myGesuad 0.9.14 - SQL Injection via Name Field and ID Parameter
CVE-2009-1810
myColex 1.4.2 - SQL Injection via formUser Parameter
CVE-2009-1804
VideoScript.us YouTube Video Script - SQL Injection via Username or Password Parameter
CVE-2009-1799
ST-Gallery 0.1 alpha - SQL Injection via gallery_category or gallery_show Parameter
CVE-2009-1787
PHP Dir Submit - SQL Injection via Username and Password Parameters
CVE-2009-1778
BigACE CMS 2.5 - SQL Injection via Username Parameter
CVE-2009-1766
LightOpenCMS 0.1 - SQL Injection via id Parameter
CVE-2009-1764
MaxCMS 2.0 - SQL Injection via id Parameter in digg Action
CVE-2009-1751
Realty Webware Technologies Web-Base 1.0 - SQL Injection via list_list.php id Parameter
CVE-2009-1747
26thavenue bSpeak 1.10 - SQL Injection via ForumID Parameter
CVE-2009-1746
Dian Gemilang DGNews 3.0 Beta - SQL Injection via berita.php id Parameter
CVE-2009-1742
PC4Arb Pc4 Uploader <= 9.0 - SQL Injection via id Parameter Filter Bypass
CVE-2009-1741
DM FileManager 3.9.2 - SQL Injection via Username or Password Field
CVE-2009-1736
Joomla com_gsticketsystem - SQL Injection via catid Parameter
CVE-2009-1734
VidSharePro - SQL Injection via catid Parameter
CVE-2009-1731
MLFFAT 2.1 - SQL Injection via Base64-Encoded Supervisor Cookie
CVE-2009-1662
Wright Way Services Recipe Script 5 - SQL Injection via Username and Password Fields
CVE-2009-1661
uTopic 1.0 - SQL Injection via Rating Parameter
CVE-2009-1658
Realty Webware Technologies Realty Web-Base 1.0 - SQL Injection via Username and Password Parameters
CVE-2009-1657
b2evolution starrating_plugin < 0.7.6 - SQL Injection
CVE-2009-1655
Easy Scripts Answer and Question Script - Authenticated SQL Injection via Userid Parameter
Details
Vulnerabilities 19,930
Exploit Likelihood High