CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,952 vulnerabilities with CWE-89
CVE-2008-5874
Hotel Booking Reservation System - Joomla! SQL Injection
CVE-2008-5865
Hotel Booking Reservation System 1.0.0 - com_hbssearch - SQL Injection
CVE-2008-5864
com_tophotelmodule 1.0 - SQL Injection via id Parameter
CVE-2008-5863
Woltlab Burning Board 3.0 - SQL Injection
CVE-2008-5859
Constructr CMS <3.02.5 - SQL Injection
CVE-2008-5851
MyPBS - SQL Injection via seasonID Parameter
CVE-2008-5841
iGaming CMS < 1.5 - SQL Injection via browse Parameter
CVE-2008-5838
E-Php Scripts E-Shop - SQL Injection
CVE-2008-2381
GForge 4.5-4.6 - SQL Injection via GroupJoinRequest Comments Variable
CVE-2008-5820
eDreamers eDNews 2 - SQL Injection via newsid Parameter
CVE-2008-5817
Web Scribble Solutions webClassifieds 2005 - SQL Injection
CVE-2008-5816
ILIAS < 3.7.4 - SQL Injection via ref_id Parameter
CVE-2008-5815
phpAlumni - SQL Injection via Acomment.php id Parameter
CVE-2008-5813
SPIP 1.8-1.8.3b 1.9-1.9.2g 2.0-2.0.2 - SQL Injection via ID Parameter
CVE-2008-5811
Joomla com_paxgallery 0.1 - SQL Injection via gid Parameter
CVE-2008-5806
DeltaScripts PHP Classifieds <7.5 - SQL Injection
CVE-2008-5805
DeltaScripts PHP Classifieds <7.5 - SQL Injection
CVE-2008-5804
e-topbiz Number Links 1 - SQL Injection
CVE-2008-5803
E-topbiz Online Store 1.0 - SQL Injection
CVE-2008-5802
E-topbiz Online Store 1.0 - SQL Injection
CVE-2008-5800
TYPO3 fsmi_people <0.0.24 - SQL Injection
CVE-2008-5798
TYPO3 cms_poll <0.1.1 - SQL Injection
CVE-2008-5797
advCalendar Extension < 0.3.1 - SQL Injection
CVE-2008-5796
TYPO3 eluna Page Comments <1.1.2 - SQL Injection
CVE-2008-5788
Domain Seller Pro 1.5 - SQL Injection
Details
Vulnerabilities 19,952
Exploit Likelihood High