CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,954 vulnerabilities with CWE-89
CVE-2008-4768
TLM CMS 3.1 - SQL Injection via nom Parameter
CVE-2008-4766
Oxygen Bulletin Board 1.1.3 - SQL Injection via Member Parameter
CVE-2008-4765
osCommerce Poll Booth Add-On 2.0 - SQL Injection via pollID Parameter
CVE-2008-4760
Graphiks MyForum 1.3 - SQL Injection via lecture.php id Parameter
CVE-2008-4757
php-daily - SQL Injection via id or prev Parameter
CVE-2008-4755
PozScripts Classified Auctions Script - SQL Injection via gotourl.php id Parameter
CVE-2008-4754
Scripts for Sites Ez Forum - SQL Injection via Forum Parameter
CVE-2008-4753
AJ Square RSS Reader - SQL Injection via EditUrl.php url Parameter
CVE-2008-4746
Uniwin eCart Professional 2.0.17 - SQL Injection via search.asp and cartUtil.asp
CVE-2008-4744
DXShopCart 4.30mc - SQL Injection via product_detail.php pid Parameter
CVE-2008-4743
QuidaScript FAQ Management Script - SQL Injection via catid Parameter
CVE-2008-4738
MyCard 1.0.2 - SQL Injection via Gallery.php ID Parameter
CVE-2008-4736
RPG.Board <= 0.8 Beta2 - SQL Injection via showtopic Parameter
CVE-2008-4732
WP Comment Remix Plugin < 1.4.4 - SQL Injection via p Parameter
CVE-2008-4717
ZEELYRICS 2.0 - SQL Injection via bannerclick.php adid Parameter
CVE-2008-4716
PHP-Lance 1.52 - SQL Injection via show.php catid Parameter
CVE-2008-4715
jpad 1.0 - SQL Injection via cid Parameter
CVE-2008-4713
212cafe Board 0.07 - SQL Injection via qID Parameter
CVE-2008-4711
Joovili < 3.0 - SQL Injection via id Parameter
CVE-2008-4709
Pilot Group eTraining - SQL Injection via News Read ID Parameter
CVE-2008-4706
vbgooglemap 1.0.3 - SQL Injection via mapid Parameter
CVE-2008-4705
MyPHPDating - SQL Injection via success_story.php id Parameter
CVE-2008-4703
BosDev BosNews 4.0 - SQL Injection via news.php article Parameter
CVE-2008-4701
Liberia CMS 1.12 - SQL Injection via libera_staff_user Cookie Parameter
CVE-2008-4700
Liberia CMS < 1.12 - SQL Injection via libera_staff_pass Cookie Parameter
Details
Vulnerabilities 19,954
Exploit Likelihood High