CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,951 vulnerabilities with CWE-89
CVE-2008-6326
Simple Customer - SQL Injection via Email Parameter
CVE-2008-6324
CF_Forum - SQL Injection via categorynbr Parameter
CVE-2008-6323
CFMSource CF_Auction - SQL Injection via forummessages.cfm categorynbr Parameter
CVE-2008-6322
CFMSource CFMBlog - SQL Injection via categorynbr Parameter
CVE-2008-6320
CF Shopkart 5.2.2 - SQL Injection via Category Parameter
CVE-2008-6319
CF_Calendar - SQL Injection via calid Parameter
CVE-2008-6314
phpBB Tag Board < 4.0 - SQL Injection via id Parameter
CVE-2008-6312
ProQuiz 1.0 - SQL Injection via Username Parameter
CVE-2008-6311
Butterfly Organizer 2.0.1 - SQL Injection via mytable Parameter
CVE-2008-6310
W3matter RevSense 1.0 - SQL Injection via f[password] Parameter
CVE-2008-6309
W3matter AskPert - SQL Injection via f[password] Parameter
CVE-2008-6304
xt-commerce < 3.0.4 Sp2.1 - SQL Injection
CVE-2008-6303
ToursManager - SQL Injection via tourid Parameter
CVE-2008-6301
Small ShoutBox 1.4 - SQL Injection via id Parameter
CVE-2008-6289
Tours Manager 1.0 - SQL Injection via cityid Parameter
CVE-2008-6286
Active Newsletter 4.3 - SQL Injection via Email or Password Parameter
CVE-2008-6285
PHP TV Portal < 2.0 - SQL Injection via mid Parameter
CVE-2008-6284
Z1Exchange 1.0 - SQL Injection via Edit.php Site Parameter
CVE-2008-6282
CMS Ortus < 1.13 - Authenticated SQL Injection via City Parameter
CVE-2008-6281
bluo_cms 1.2 - SQL Injection via id Parameter
CVE-2008-6277
RakhiSoftware Shopping Cart - SQL Injection via product.php subcategory_id Parameter
CVE-2008-6276
User Karma module < 5.x-1.13 and 6.x-1.0-beta1 - Authenticated SQL Injection via Content Type or Voting API Value
CVE-2008-6274
FamilyProject 2.0 - SQL Injection via Login or Password Parameter
CVE-2008-6272
Dragan Mitic Apoll 0.7 beta and 0.7.5 - SQL Injection via Admin Index Pass Parameter
CVE-2008-6270
Dragan Mitic Apoll 0.7 beta and 0.7.5 - SQL Injection via User Parameter
Details
Vulnerabilities 19,951
Exploit Likelihood High