CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,930 vulnerabilities with CWE-89
CVE-2009-1403
CRE Loaded 6.2 - SQL Injection via products_id Parameter
CVE-2009-1362
chcounter 3.1.3 - SQL Injection via login_name Parameter
CVE-2009-1347
chCounter 3.1.3 - SQL Injection via Login Name or Password Parameter
CVE-2009-1346
NetHoteles 3.0 - SQL Injection via id_establecimiento Parameter
CVE-2009-1345
cpCommerce 1.2.8 - SQL Injection via id_document Parameter
CVE-2009-1323
Web File Explorer 3.1 - SQL Injection via id Parameter
CVE-2009-1317
Aqua CMS 1.1 - SQL Injection via userSID Cookie or Username Parameter
CVE-2009-1316
AbleSpace 1.0 - SQL Injection via eid or id Parameter
CVE-2009-1282
glFusion <= 1.1.2 - SQL Injection via glf_session Cookie Parameter
CVE-2009-1277
Gravity Board X 2.0 BETA - SQL Injection via member_id Parameter
CVE-2009-1263
com_bookjoomlas 0.1 - SQL Injection via gbid Parameter
CVE-2009-1259
Insane Visions AdaptBB 1.0 - SQL Injection via topic_id Parameter
CVE-2009-1258
RD-Autos (com_rdautos) 1.5.7 - SQL Injection via makeid Parameter
CVE-2009-1256
FlexCMS 2.5 - SQL Injection via ItemId Parameter
CVE-2009-1247
Acutecp - SQL Injection
CVE-2009-1245
CCCP Community Clan Portal Pastebin < 2.80 - SQL Injection via Subject, Language, or Nickname Parameters
CVE-2009-1229
arcadwy_arcade_script - SQL Injection via User Cookie Parameter
CVE-2009-1224
vsp_stats_processor 0.45 - SQL Injection via gameID Parameter
CVE-2009-1208
auth2db 0.2.5 - SQL Injection via Multibyte Character Encoding
CVE-2009-1066
Pixie CMS 1.01a - SQL Injection via Referer HTTP Header
CVE-2009-1065
Pixie CMS 1.01a - SQL Injection via Index.php X Parameter
CVE-2009-1049
Bloginator 1A - SQL Injection via articleCall.php id Parameter
CVE-2009-1038
YAP Blog 1.1.1 - SQL Injection via Image ID Parameter
CVE-2009-1034
Drupal Tasklist < 5.x-1.3 and 5.x-2.x < 5.x-2.0-alpha1 - SQL Injection via URI Values
CVE-2009-1033
DeluxeBB <= 1.3 - SQL Injection via qorder Parameter
Details
Vulnerabilities 19,930
Exploit Likelihood High