CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,951 vulnerabilities with CWE-89
CVE-2008-6165
CSPartner 0.1 - SQL Injection via Pseudo or Passe Parameters
CVE-2008-6156
AdMan 1.1.20070907 - Authenticated SQL Injection via editCampaign.php campaignId Parameter
CVE-2008-6155
Hispah Text Links Ads 1.1 - SQL Injection via idtl Parameter
CVE-2008-6154
Hispah Text Links Ads 1.1 - SQL Injection via idcat Parameter
CVE-2008-6153
Jay Patel Pixel8 Web Photo Album 3.0 - SQL Injection via AlbumID Parameter
CVE-2008-6152
SepCity Faculty Portal - SQL Injection via deptdisplay.asp ID Parameter
CVE-2008-6151
SepCity Shopping Mall - SQL Injection via shpdetails.asp ID Parameter
CVE-2008-6150
SepCity Classified Ads - SQL Injection via ID Parameter
CVE-2008-6149
com_mdigg 2.2.8 - SQL Injection via cagtegory Parameter
CVE-2008-6148
Live Ticker (com_liveticker) 1.0 for Joomla! - SQL Injection via tid Parameter
CVE-2008-6146
DeluxeBB < 1.2 - SQL Injection via Delete Action Parameter
CVE-2008-6145
WEC Discussion Forum < 1.7.0 - SQL Injection
CVE-2008-6142
FlexPHPic <0.0.4 - FlexPHPic Pro <0.0.3 - SQL Injection
CVE-2008-6134
EveryBlog 5.x and 6.x - SQL Injection
CVE-2008-6133
Full PHP Emlak Script - SQL Injection
CVE-2008-6124
Moodle <1.6.7-1.9.2 - SQL Injection
CVE-2008-6120
SocialEngine < 2.7 - SQL Injection via Profile Comments Parameter
CVE-2008-6117
PG Job Site Pro - SQL Injection via poll_view_id Parameter
CVE-2008-6116
EXtrovert Software Thyme 1.0 - SQL Injection
CVE-2008-6115
Prozilla Hosting Index - SQL Injection
CVE-2008-6114
Mytipper Zogo-shop <1.15.4 - SQL Injection
CVE-2008-6111
NetArt Media Vlog System 1.1 - SQL Injection
CVE-2008-6104
A4Desk PHP Event Calendar - SQL Injection
CVE-2008-6102
Link Trader Script - SQL Injection via lnkid Parameter
CVE-2008-6101
Adult Banner Exchange Website - SQL Injection
Details
Vulnerabilities 19,951
Exploit Likelihood High