CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,952 vulnerabilities with CWE-89
CVE-2008-5653
MyioSoft AjaxPortal 3.0 - SQL Injection
CVE-2008-5652
MyioSoft EasyBookMarker 4.0 - SQL Injection
CVE-2008-5651
MyioSoft EasyBookMarker 4.0 - SQL Injection
CVE-2008-5650
AlstraSoft Web Host Directory - SQL Injection
CVE-2008-5649
AlstraSoft Article Manager Pro 1.6 - SQL Injection
CVE-2008-5648
DeltaScripts PHP Shop 1.0 - SQL Injection
CVE-2008-5643
Joomla com_books - SQL Injection via book_id Parameter
CVE-2008-5641
Active Photo Gallery 6.2 - SQL Injection
CVE-2008-5640
Active Bids 3.5 - SQL Injection via ItemID Parameter
CVE-2008-5638
Active Price Comparison 4 - SQL Injection
CVE-2008-5637
ParsBlogger - SQL Injection via blog.asp wr Parameter
CVE-2008-5636
Lito Lite CMS - SQL Injection via cid Parameter
CVE-2008-5635
Active Membership 2.0 - SQL Injection
CVE-2008-5634
Active Force Matrix 2.0 - SQL Injection
CVE-2008-5633
ActiveVotes 2.2 - SQL Injection via Username and Password Parameters
CVE-2008-5632
Active Time Billing 3.2 - SQL Injection
CVE-2008-5631
Active eWebquiz 8.0 - SQL Injection
CVE-2008-5630
Post Affiliate Pro <3,3.1.4 - SQL Injection
CVE-2008-5629
Turnkey Arcade Script - SQL Injection
CVE-2008-5628
little_cms 0.0.1 - SQL Injection via Index.php Term Parameter
CVE-2008-5627
Active Trade 2 - SQL Injection via Username or Password Parameter
CVE-2008-5609
Commerce extension <0.9.6 - SQL Injection
CVE-2008-5607
JMovies 1.1 - SQL Injection via id Parameter
CVE-2008-5605
ASP Portal - SQL Injection
CVE-2008-5599
Merlix Teamworx Server - SQL Injection
Details
Vulnerabilities 19,952
Exploit Likelihood High