CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,965 vulnerabilities with CWE-89
CVE-2008-4161
Assetman 2.5b - SQL Injection via search_inv.php order and order_by Parameters
CVE-2008-4173
ProArcadeScript 1.3 - SQL Injection via Random Parameter
CVE-2008-4172
Cars & Vehicle Script - SQL Injection via lnkid Parameter
CVE-2008-4171
Invision Power Board 2.2.x-2.3.x - SQL Injection via xmlout.php Name Parameter
CVE-2008-4169
iScripts EasyIndex - SQL Injection via detaillist.php produid Parameter
CVE-2008-4159
Jaw Portal and Zanfi CMS Lite - SQL Injection via Page Parameter
CVE-2008-4157
Vastal I-Tech phpVID 1.1 and 1.2.3 - SQL Injection via groups.php cat Parameter
CVE-2008-4156
CustomCms Gaming Portal 4.0 - SQL Injection via print.php id Parameter
CVE-2008-4154
webEdition CMS - SQL Injection via we_objectID Parameter
CVE-2008-4093
YourOwnBux 3.1 and 3.2 beta - SQL Injection via User Parameter
CVE-2008-4092
myphpnuke < 1.8.8_8 - SQL Injection via printfeature.php artid Parameter
CVE-2008-4091
Web Directory Script 1.5.3 - SQL Injection via Site Parameter in Open Action
CVE-2008-4090
PHP Coupon Script 4.0 - SQL Injection via id Parameter in addtocart Action
CVE-2008-4088
myphpnuke < 1.8.8_8 - SQL Injection via print.php sid Parameter
CVE-2008-4086
Reciprocal Links Manager 1.1 - SQL Injection via Site Parameter
CVE-2008-4084
MyioSoft EasyClassifields 3.0 - SQL Injection via go Parameter in browse Action
CVE-2008-4082
Brim 2.0.0 - Authenticated SQL Injection via Tasks Plugin Search Action
CVE-2008-4080
Stash 1.0.3 - SQL Injection via Username or Download Parameter
CVE-2008-4078
LedgerSMB < 1.2.15 and SQL-Ledger < 2.8.17 - Authenticated SQL Injection
CVE-2008-4074
Zanfi Autodealers CMS AutOnline - SQL Injection via index.php id Parameter
CVE-2008-4073
Zanfi Autodealers CMS AutOnline - SQL Injection via pageid Parameter
CVE-2008-4072
phsBlog 0.2 - SQL Injection via sid or sql_cid Parameter
CVE-2008-4055
Million Pixel Script - SQL Injection via tops_top.php id_cat Parameter
CVE-2008-4054
Kolifa Download Script 1.2 - SQL Injection via id Parameter
CVE-2008-4046
eliteCMS 1.0 - SQL Injection via Page Parameter
Details
Vulnerabilities 19,965
Exploit Likelihood High