CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,968 vulnerabilities with CWE-89
CVE-2008-3347
MyioSoft EasyDynamicPages <3.0 - SQL Injection
CVE-2008-3306
C. Desseno YouTube Blog (ytb) 0.1 - SQL Injection
CVE-2008-3307
C. Desseno YouTube Blog ytb 0.1 - SQL Injection
CVE-2008-3309
digileave < 1.2 - SQL Injection via info_book.asp book_id Parameter
CVE-2008-3310
Pre Survey Poll - SQL Injection via catid Parameter
CVE-2008-3297
SocialEngine < 2.83 - SQL Injection via se_user or se_admin Cookie
CVE-2008-3302
BilboBlog 0.2.1 - Authenticated SQL Injection via admin/delete.php num Parameter
CVE-2008-3291
AproxEngine 5.1.0.4 - SQL Injection
CVE-2008-3265
DT Register (com_dtregister) 2.2.3 - SQL Injection
CVE-2008-3266
SoftAcid Hotel Reservation System Multi - SQL Injection via picture_pic_bv.asp key Parameter
CVE-2008-3267
mojoJobs - SQL Injection via cat_a Parameter
CVE-2008-3254
preCMS 1 - SQL Injection via UserProfil id Parameter
CVE-2008-3256
Siteframe CMS <3.2.3 & Siteframe Beaumont <5.0.5 - SQL Injection
CVE-2008-3258
Zoph - SQL Injection
CVE-2008-3250
Arctic Issue Tracker 2.0.0 - SQL Injection
CVE-2008-3251
tplSoccerSite 1.0 - SQL Injection via Multiple Parameters
CVE-2008-3238
ITechBids 7.0 Gold - SQL Injection via seller_id, productid, or id Parameter
CVE-2008-3240
AlstraSoft Affiliate Network Pro - SQL Injection
CVE-2008-3241
UltraStats <0.2.142 - SQL Injection
CVE-2008-3245
phpHoo3 - SQL Injection via viewCat Parameter
CVE-2008-3223
Drupal 6.x < 6.3 - SQL Injection via Numeric Field Placeholder
CVE-2008-3206
Yuhhu Pubs Black Cat - SQL Injection
CVE-2008-3212
Scripteen Free Image Hosting Script 1.2.1 - SQL Injection
CVE-2008-3213
WebCMS Portal Edition - SQL Injection
CVE-2008-3200
avlc_forum - SQL Injection via id Parameter in affich_message Action
Details
Vulnerabilities 19,968
Exploit Likelihood High