CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,944 vulnerabilities with CWE-89
CVE-2009-0672
RavenNuke 2.30 - Authenticated SQL Injection via Resend_Email Module user_prefix Parameter
CVE-2009-0646
4site CMS < 2.6 - SQL Injection via Multiple Parameters
CVE-2009-0604
php_director < 0.21 - SQL Injection via Searching Parameter
CVE-2009-0598
PhpMesFilms 1.0 and 1.8 - SQL Injection via id Parameter
CVE-2009-0597
w3b_cms < 3.3.0 - SQL Injection via Username Parameter
CVE-2009-0593
plx Auto Reminder 3.7 - SQL Injection
CVE-2009-0574
Easy CafeEngine - SQL Injection via catid Parameter
CVE-2009-0543
ProFTPD Server <1.3.1 - Auth Bypass
CVE-2009-0542
ProFTPD Server <1.3.2rc2 - SQL Injection
CVE-2009-0534
FlexCMS - SQL Injection via catId Parameter
CVE-2009-0531
A Better Member-Based ASP Photo Gallery <1.2 - SQL Injection
CVE-2009-0528
Rhadrix If-CMS <2.07 - SQL Injection
CVE-2009-0516
BusinessSpace < 1.2 - SQL Injection via Classified Page id Parameter
CVE-2009-0462
ClickTech ClickCart 6.0 - SQL Injection
CVE-2009-0459
Whole Hog Password Protect: Enhanced 1.x - SQL Injection
CVE-2009-0458
Whole Hog Ware Support 1.x - SQL Injection
CVE-2009-0454
DMXReady Online Notebook Manager 1.1 - SQL Injection
CVE-2009-0452
Online Grades 3.2.4 - SQL Injection
CVE-2009-0451
Skalfa SkaLinks 1.5 - SQL Injection
CVE-2009-0447
MyDesign Sayac 2.0 - SQL Injection via User or Pass Parameter
CVE-2009-0446
WEBalbum 2.4b - SQL Injection via photo.php id Parameter
CVE-2009-0445
Dreampics Gallery Builder - SQL Injection
CVE-2009-0494
com_portfol 1.2 - SQL Injection via vcatid Parameter
CVE-2009-0493
IT!CMS < 0.21-alpha - SQL Injection via Username Parameter
CVE-2009-0479
Online Grades 3.2.4 - SQL Injection
Details
Vulnerabilities 19,944
Exploit Likelihood High