CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,968 vulnerabilities with CWE-89
CVE-2008-3204
E-topbiz Million Pixels 3 - SQL Injection
CVE-2008-3189
DreamNews Manager - SQL Injection via id Parameter
CVE-2008-3191
mForum 0.1a - SQL Injection via User Profile Fields
CVE-2008-3193
jSite 1.0 OE - SQL Injection via Page Parameter
CVE-2008-3185
Relative Real Estate Systems <3.0 - SQL Injection
CVE-2008-3151
PHP-Nuke 4ndvddb 0.91 - SQL Injection
CVE-2008-3152
SmartPPC and SmartPPC Pro - SQL Injection via idDirectory Parameter
CVE-2008-3153
Triton CMS Pro < 1.0.6 - SQL Injection via X-Forwarded-For Header
CVE-2008-3154
WebBlizzard CMS - SQL Injection via Page Parameter
CVE-2008-3129
Catviz 0.4 beta 1 - SQL Injection via Foreign Key Value or Webpage Parameter
CVE-2008-3131
powie psys 0.7.0 Alpha - SQL Injection via chatbox.php showid Parameter
CVE-2008-3132
Joomla com_beamospetition - SQL Injection via Pet Parameter
CVE-2008-3133
BareNuked CMS 1.1.0 - SQL Injection
CVE-2008-3136
AShop Deluxe 4.x - SQL Injection via Catalogue.php Cat Parameter
CVE-2008-3119
DreamPics Builder - SQL Injection via Page Parameter
CVE-2008-3122
Xerox CentreWare Web <4.6.46 - SQL Injection
CVE-2008-3123
Mole Group Real Estate Script <1.1 - SQL Injection
CVE-2008-3124
Mole Group Hotel Script 1.0 - SQL Injection
CVE-2008-3125
Mole Group Lastminute Script 4.0 - SQL Injection
CVE-2008-3118
phpmotion < 2.0 - SQL Injection via vid Parameter
CVE-2008-3089
Xpoze Pro 3.06 - SQL Injection via uid Parameter
CVE-2008-3090
BlognPlus 2.5.5 - SQL Injection via p, e, d, or m Parameters
CVE-2008-3092
Drupal Taxonomy Autotagger Module < 5.x-1.8 - Authenticated SQL Injection
CVE-2008-3083
brightcode_weblinks_module - SQL Injection via catid Parameter
CVE-2008-3070
MyBB < 1.2.12 - SQL Injection via User Language Variable
Details
Vulnerabilities 19,968
Exploit Likelihood High