CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,954 vulnerabilities with CWE-89
CVE-2008-4675
phpcounter <= 1.3.2 - SQL Injection via Name Parameter
CVE-2008-4674
Conkurent Real Estate Manager 1.01 - SQL Injection via cat_id Parameter
CVE-2008-4666
Ultimate Webboard 3.00 - SQL Injection via Category Parameter
CVE-2008-4665
PG Matchmaking - SQL Injection via id Parameter
CVE-2008-4660
M1 Intern 1.0.0 - SQL Injection
CVE-2008-4659
mannschaftsliste < 1.0.3 - SQL Injection
CVE-2008-4658
TYPO3 JobControl < 1.15.4 - SQL Injection
CVE-2008-4657
TYPO3 Econda Plugin <= 0.0.2 - SQL Injection
CVE-2008-4656
TYPO3 Frontend Users View < 0.1.6 - SQL Injection
CVE-2008-4655
TYPO3 simplesurvey < 1.7.0 - SQL Injection
CVE-2008-4653
Makale 0.26 - SQL Injection via id Parameter
CVE-2008-4651
Jetbox CMS 2.1 - Authenticated SQL Injection via orderby Parameter or nav_id Parameter
CVE-2008-4650
myEvent 1.6 - SQL Injection via viewevent.php eventdate Parameter
CVE-2008-4647
sweetCMS 1.5.2 - SQL Injection via Page Parameter
CVE-2008-4643
myWebland myStats - SQL Injection via hits.php sortby Parameter
CVE-2008-4642
AstroSPACES 1.1.1 - SQL Injection via Profile ID Parameter
CVE-2008-4633
Drupal Node Clone - Authenticated SQL Injection via Previously Cast Vote
CVE-2008-4628
myWebland miniBloggie 1.0 - SQL Injection via del.php post_id Parameter
CVE-2008-4627
rgallery_plugin 1.09 - SQL Injection via itemID Parameter
CVE-2008-4625
ShiftThis Newsletter - SQL Injection via Newsletter Parameter
CVE-2008-4623
DS-Syndicate 1.1.1 - SQL Injection via feed_id Parameter
CVE-2008-4621
ZeeScripts Zeeproperty - SQL Injection via bannerclick.php adid Parameter
CVE-2008-4620
MRBS < 1.4 - SQL Injection via Area Parameter
CVE-2008-4617
pyxicom actualite 1.0 - SQL Injection via id Parameter
CVE-2008-4613
PortalApp 4.0 - SQL Injection via forums.asp sortby Parameter
Details
Vulnerabilities 19,954
Exploit Likelihood High