CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,954 vulnerabilities with CWE-89
CVE-2008-5122
ektron cms4000.net < 7.52 - SQL Injection via WorkArea/ContentRatingGraph.aspx res Parameter
CVE-2008-5097
MyFWB 1.0 - SQL Injection via Page Parameter
CVE-2008-5088
PHPKB Knowledge Base Software 1.5 Professional - SQL Injection via ID Parameter
CVE-2008-5087
TYPO3 Another Backend Login < 0.0.4 - SQL Injection
CVE-2008-5075
E-Uploader Pro 1.0 - SQL Injection via Multiple Parameters
CVE-2008-5074
Freshlinks 1.0 RC1 module for PHP-Fusion - SQL Injection via linkid Parameter
CVE-2008-5070
Pro Chat Rooms 3.0.3 - SQL Injection via gud Parameter
CVE-2008-5069
Panuwat PromoteWeb MySQL - SQL Injection via go.php id Parameter
CVE-2008-5064
H&H WebSoccer 2.80 - SQL Injection via liga.php id Parameter
CVE-2008-5058
Pre Simple CMS - SQL Injection via User Parameter
CVE-2008-5057
Yigit Aybuga Dizi Portali - SQL Injection via film Parameter
CVE-2008-5055
ActiveCampaign TrioLive < 1.58.7 - SQL Injection via department_id Parameter
CVE-2008-5054
Develop It Easy Membership System 1.3 - SQL Injection via Email or Password Parameter
CVE-2008-5051
JooBlog 0.1.1 - SQL Injection via PostID Parameter
CVE-2008-5047
Mole Group Rental Script - SQL Injection via Username Parameter
CVE-2008-5046
Mole Group Pizza Script - SQL Injection via manufacturers_id Parameter
CVE-2008-5037
ElkaGroup Image Gallery 1.0 - SQL Injection via view.php cid Parameter
CVE-2008-5004
myWebland Bloggie Lite 0.0.2 beta - SQL Injection via Cookie
CVE-2008-5003
Shahrood - SQL Injection via id Parameter
CVE-2008-5000
PHPX 3.5.16 - SQL Injection via News ID Parameter
CVE-2008-4991
EC-CUBE < 1.3.5, < 1.4.7, < 1.5.0 - SQL Injection
CVE-2008-4906
Lyrics (lyrics_menu) plugin 0.42 for e107 - SQL Injection via l_id Parameter
CVE-2008-4904
Typo < 5.1.3 - Authenticated SQL Injection via Manage Pages Search Parameter
CVE-2008-4902
Article Publisher Pro 1.5 - SQL Injection via Userid Parameter
CVE-2008-4901
Article Publisher Pro 1.5 - SQL Injection via Username Parameter
Details
Vulnerabilities 19,954
Exploit Likelihood High