CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,952 vulnerabilities with CWE-89
CVE-2008-6029
buzzywall <= 1.3.1 - SQL Injection via Search Parameter
CVE-2008-6028
University of Queensland Library Fez <2.0 RC1 - SQL Injection
CVE-2008-6026
BlueCUBE CMS - SQL Injection via tienda.php id Parameter
CVE-2008-6020
Drupal 6.x < 6.x-2.2 - SQL Injection
CVE-2008-6019
EACOMM DO-CMS 3.0 - SQL Injection via p Parameter
CVE-2008-6017
i-rater_basic - SQL Injection via idp Parameter
CVE-2008-6016
EsFaq 2.0 - SQL Injection via cid Parameter
CVE-2008-6015
EsFaq 2.0 - SQL Injection via Search Keywords or Category Parameters
CVE-2008-6014
Rianxosencabos CMS 0.9 - SQL Injection
CVE-2008-6013
Freeway < 1.4.3.210 - SQL Injection via Advanced Search and Service Resource Pages
CVE-2008-6011
SG Real Estate Portal 2.0 - SQL Injection
CVE-2008-6007
QuidaScript BookMarks Favourites Script - SQL Injection
CVE-2008-6003
AJ Auction Pro Platinum 2 - SQL Injection
CVE-2008-5998
Drupal Ajax Checklist <5.x-1.1 - SQL Injection
CVE-2008-5992
Jetik Emlak Sistem A 2.0 - SQL Injection via KayitNo Parameter
CVE-2008-5988
Jadu CMS for Government - SQL Injection via recruit_details.php id Parameter
CVE-2008-5978
Ocean12 Mailing List Manager Gold - SQL Injection
CVE-2008-5977
PHP JOBWEBSITE PRO - SQL Injection via adname Parameter
CVE-2008-5975
Active Price Comparison 4.0 - SQL Injection
CVE-2008-5974
Active Price Comparison 4.0 - SQL Injection
CVE-2008-5973
Active Web Mail 4.0 - SQL Injection
CVE-2008-5972
Active Business Directory 2 - SQL Injection
CVE-2008-5970
i-Net Solution Orkut Clone - SQL Injection
CVE-2008-5969
Sunbyte e-Flower - SQL Injection via popupproduct.php id Parameter
CVE-2008-5960
Tribiq CMS Community <5.0.11E - SQL Injection
Details
Vulnerabilities 19,952
Exploit Likelihood High