CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,954 vulnerabilities with CWE-89
CVE-2008-5336
WebStudio CMS - SQL Injection via pageid Parameter
CVE-2008-5335
PHP-Fusion 6.01.15/7.00.1 - SQL Injection
CVE-2008-5333
NitroTech 0.0.3a - SQL Injection via members.php id Parameter
CVE-2008-5321
GesGaleri - SQL Injection via Index.php No Parameter
CVE-2008-5320
e107 < 0.7.13 - Authenticated SQL Injection via ue[] Parameter
CVE-2008-3058
Octeth Oempro 3.5.5.1 - SQL Injection via FormValue_Email or FormValue_SearchKeywords Parameter
CVE-2008-5311
NetArt Media Blog System 1.5 - SQL Injection
CVE-2008-5310
NetArt Media Car Portal 2.0 - SQL Injection
CVE-2008-5309
NetArt Media Real Estate Portal 1.2 - SQL Injection
CVE-2008-5307
PG Roommate Finder Solution - SQL Injection
CVE-2008-5306
PG Real Estate Solution - SQL Injection
CVE-2008-5295
Jamit Job Board 3.4.10 - SQL Injection
CVE-2008-5294
WebStudio eCatalogue - SQL Injection
CVE-2008-5293
WebStudio eHotel - SQL Injection via PageID Parameter
CVE-2008-5292
VideoGirls BiZ - SQL Injection via view_snaps.php type Parameter
CVE-2008-5289
Clean CMS 1.5 - SQL Injection via full_txt.php id Parameter
CVE-2008-5287
Werner Hilversum FAQ Manager 1.2 - SQL Injection
CVE-2008-5273
Todd Woolums ASP News Mgmt 2.2 - SQL Injection
CVE-2008-5270
Yuhhu Superstar 2008 - SQL Injection
CVE-2008-5269
powie psys 0.7.0 alpha - SQL Injection via shownews Parameter
CVE-2008-5268
ASPPortal - SQL Injection via Topic_Id Parameter
CVE-2008-5267
Experts 1.0.0 - SQL Injection via Question ID Parameter
CVE-2008-2429
Calendarix Basic 0.8.20071118 - SQL Injection via catsearch or catview Parameter
CVE-2008-5226
MambAds 1.0 RC1 Beta and 1.0 RC1 - SQL Injection via ma_cat Parameter
CVE-2008-5223
Airaev Commerce 3.0 - SQL Injection
Details
Vulnerabilities 19,954
Exploit Likelihood High