CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,944 vulnerabilities with CWE-89
CVE-2008-6622
webbdomian post_card < 1.02 - SQL Injection via choosecard.php catid Parameter
CVE-2008-6618
ClassSystem 2.3 - SQL Injection via teacher_id and message_id Parameters
CVE-2008-6615
Zen Cart 2008 - SQL Injection via Advanced Search Keyword Parameter
CVE-2008-6614
Implied By Design Micro CMS 3.5 - SQL Injection via Login Username or Password Parameter
CVE-2008-6611
Minimal ABlog 0.4 - SQL Injection via id Parameter
CVE-2008-6608
DevelopItEasy Events Calendar 1.2 - SQL Injection via User Name, User Pass, or ID Parameter
CVE-2008-6606
MatPo Link 1.2 Beta - SQL Injection via id Parameter
CVE-2008-6596
PHCDownload 1.1 - SQL Injection via Admin Index Hash Parameter
CVE-2008-6595
pmk_rssnewsexport_extension - SQL Injection
CVE-2008-6594
cm_rdfexport for TYPO3 - SQL Injection
CVE-2008-6593
LightNEasy SQLite <= 1.2.2 - SQL Injection via dlid Parameter
CVE-2008-6582
Miniweb 2.0 - SQL Injection via Username Parameter
CVE-2008-6573
Avaya Communication Manager 3.x-5.0 - SQL Injection via SIP Personal Information Manager
CVE-2008-6572
AbleDating 2.4 - SQL Injection via search_results.php Keyword Parameter
CVE-2008-6527
GO4I.NET ASP Forum 1.0 - SQL Injection via iFor Parameter
CVE-2008-6526
BosDev BosClassifieds - SQL Injection via cat_id Parameter
CVE-2008-6525
Nice PHP FAQ Script - SQL Injection via Admin Panel Password Parameter
CVE-2008-6517
NewsHOWLER 1.03 Beta - SQL Injection via news_user Cookie Parameter
CVE-2008-6509
Openfire < 3.6.0a - SQL Injection via SIP Plugin CallLogDAO Type Parameter
CVE-2008-6489
com_myalbum 1.0 - SQL Injection via Album Parameter
CVE-2008-6488
SoftComplex PHP Image Gallery 1.0 - SQL Injection via Admin Field in Login Action
CVE-2008-6487
DigiAffiliate < 1.4 - SQL Injection via Login Admin and Password Fields
CVE-2008-6485
SoftComplex PHP Image Gallery - SQL Injection via ctg Parameter
CVE-2008-6484
Mole Group Taxi Calc Dist Script - SQL Injection via login.php User Field
CVE-2008-6481
com_versioning 1.0.2 - SQL Injection via id Parameter
Details
Vulnerabilities 19,944
Exploit Likelihood High