CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,944 vulnerabilities with CWE-89
CVE-2008-6694
Random Prayer (ste_prayer) 0.0.1 - SQL Injection
CVE-2008-6693
sb_downloader < 0.1.4 - SQL Injection
CVE-2008-6692
Diocese of Portsmouth Training Courses (pd_trainingcourses) 0.1.1 - SQL Injection
CVE-2008-6691
Diocese of Portsmouth Calendar Today 0.0.3 - SQL Injection
CVE-2008-6689
dmmjobcontrol < 1.15.0 - SQL Injection
CVE-2008-6686
CoolURI < 1.0.11 - SQL Injection
CVE-2008-6678
QuickerSite 1.8.5 - SQL Injection via sNickName Parameter
CVE-2008-6663
PHPAuctions - SQL Injection via profile.php auction_id Parameter
CVE-2008-6656
Open Auto Classifieds 1.4.3b - SQL Injection via Listings ID Parameter or Login Username Field
CVE-2008-6653
com_webhosting < 1.1 - SQL Injection via catid Parameter
CVE-2008-6652
OneCMS 2.5 - SQL Injection via sitename Parameter
CVE-2008-6649
Ktools PhotoStore <= 3.5.2 - SQL Injection via id Parameter
CVE-2008-6648
Ktools PhotoStore 3.4.3 and 3.5.2 - SQL Injection via gid Parameter
CVE-2008-6647
Ktools PhotoStore 3.4.3 - SQL Injection via Gallery gid Parameter
CVE-2008-6642
DotContent FluentCMS 4.x - SQL Injection via view.php sid Parameter
CVE-2008-6641
Shader TV Beta - SQL Injection via sid Parameter or Authentication Fields
CVE-2008-6640
BatmanPorTaL - SQL Injection via id Parameter
CVE-2008-6634
RoomPHPlanning 1.5 - SQL Injection via idroom Parameter
CVE-2008-6633
RoomPHPlanning 1.5 - SQL Injection via idresa Parameter
CVE-2008-6632
MercuryBoard <= 1.1.5 - SQL Injection via User-Agent HTTP Header
CVE-2008-6627
WEBDOMAIN WebShop <= 1.2 - SQL Injection via getin.php Username Parameter
CVE-2008-6626
WEBBDOMAIN Quiz <= 1.02 - SQL Injection via Username Parameter
CVE-2008-6625
WEBBDOMAIN Polls 1.0 and 1.01 - SQL Injection via Username Parameter
CVE-2008-6624
WEBBDOMAIN Petition 1.02, 2.0, 3.0 - SQL Injection via Username Parameter
CVE-2008-6623
webbdomain post_card < 1.02 - SQL Injection via Username Parameter
Details
Vulnerabilities 19,944
Exploit Likelihood High