CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,944 vulnerabilities with CWE-89
CVE-2009-0104
EZpack 4.2b2 - SQL Injection via qType Parameter
CVE-2008-10004 MEDIUM
Email Registration 5.x-2.1 - SQL Injection via namenew Argument
CVSS 6.3
CVE-2008-10003 MEDIUM
iGamingModules flashgames 1.1.0 - SQL Injection via game.php lid Parameter
CVSS 6.3
CVE-2008-7302
nBill 1.2.0 SP1 - Joomla! - SQL Injection
CVE-2008-7301
jSite 1.0 OE - SQL Injection via Username Parameter
CVE-2008-7267
SiteEngine 5.x - SQL Injection via Announcements.php id Parameter
CVE-2008-7226
PHP-Nuke Recipes Module 1.3-1.4 - SQL Injection via recipeid Parameter
CVE-2008-7210
AJchat 0.10 - SQL Injection via Numeric Parameter Hash Bypass
CVE-2008-7208
OneCMS < 2.4 - SQL Injection via Username or User Parameter
CVE-2008-7169
Jabode com_jabode - SQL Injection via id Parameter
CVE-2008-7153
Docebo < 3.5.0.3 - SQL Injection via Accept-Language HTTP Header
CVE-2008-7145
CoronaMatrix phpAddressBook 2.0 - SQL Injection via Username or Password Parameter
CVE-2008-7120
hot_links_sql-php < 3 - SQL Injection via news.php Parameter
CVE-2008-7119
WeBid 0.5.4 - SQL Injection via item.php id Parameter
CVE-2008-7116
WeBid 0.5.4 - SQL Injection via Admin Panel Username Parameter
CVE-2008-7114
iFdate < 2.0.3 - SQL Injection via Name Field
CVE-2008-7097
Qsoft K-Rate Premium - SQL Injection via Multiple Parameters
CVE-2008-7091
Pligg CMS < 9.9.0 - SQL Injection via Multiple Parameters
CVE-2008-7085
HockeySTATS Online 2.0 - SQL Injection via id or divid Parameter
CVE-2008-7083
ReVou Micro Blogging Twitter clone - SQL Injection via Username and Password Fields
CVE-2008-7077
SailPlanner 0.3a - SQL Injection via Username and Password Fields
CVE-2008-7075
Kalptaru Infotech Stararticles - SQL Injection
CVE-2008-7071
Chipmunk Topsites - SQL Injection via Username Parameter
CVE-2008-7059
One-News Beta 2 - SQL Injection via q Parameter
CVE-2008-7049
NatterChat 1.1 and 1.12 - SQL Injection via Username and Password Parameters
Details
Vulnerabilities 19,944
Exploit Likelihood High