CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,968 vulnerabilities with CWE-89
CVE-2008-3419
Youtuber Clone - SQL Injection via UID Parameter
CVE-2008-3420
Mobius for Mimsy XG <1.4.4.1 - SQL Injection
CVE-2008-3393
BookMine - SQL Injection via events_id Parameter
CVE-2008-3403
MojoPersonals - SQL Injection via cat Parameter
CVE-2008-3406
phplinkat 0.1 - SQL Injection via showcat.php catid Parameter
CVE-2008-3382
MojoClassifieds 2.0 - SQL Injection
CVE-2008-3383
mojoauto - SQL Injection via cat_a Parameter
CVE-2008-3386
AlstraSoft Video Share Enterprise 4.51 - SQL Injection
CVE-2008-3387
phpfootball 1.6 - SQL Injection via show.php dbtable Parameter
CVE-2008-3388
Def-Blog 1.0.3 - SQL Injection via Article Parameter
CVE-2008-3366
Pligg CMS Beta 9.9.0 - SQL Injection
CVE-2008-3369
ViArt Shop < 3.5 - SQL Injection via products_rss.php category_id Parameter
CVE-2008-3370
EMC Centera Universal Access <4.0_4735.p4 - SQL Injection
CVE-2008-3372
Getacoder Clone - SQL Injection via sb_protype Parameter
CVE-2008-3374
Gregarius < 0.5.4 - SQL Injection via rsargs Array Parameter
CVE-2008-3377
phpTest 0.6.3 - SQL Injection via image_id Parameter
CVE-2008-3378
Fizzmedia 1.51.2 - SQL Injection via mid Parameter
CVE-2008-3359
Owl Intranet Knowledgebase <0.95 - SQL Injection
CVE-2008-3351
Atom PhotoBlog <1.1.5b1 - SQL Injection
CVE-2008-3352
Live Music Plus 1.1.0 - SQL Injection
CVE-2008-3355
Camera Life 2.6.2 - SQL Injection via id Parameter in sitemap.xml.php
CVE-2008-3341
Jobbex JobSite - SQL Injection via jobcountryid or jobstateid Parameter
CVE-2008-3343
MyioSoft EasyPublish <3.0tr - SQL Injection
CVE-2008-3345
MyioSoft EasyE-Cards <3.10a - SQL Injection
CVE-2008-3346
ShopCart DX - SQL Injection via pid Parameter
Details
Vulnerabilities 19,968
Exploit Likelihood High