CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,971 vulnerabilities with CWE-89
CVE-2008-2510
Upload File Plugin for WordPress - SQL Injection via f_id Parameter
CVE-2008-2477
MxBB Portal 2.7.3 - SQL Injection via Page Parameter
CVE-2008-2479
phpFix 2.0 - SQL Injection via kind or account Parameter
CVE-2008-2484
Xomol CMS 1.20071213 - SQL Injection via Email Parameter
CVE-2008-2487
maxsite < 1.10 - SQL Injection via Category Parameter
CVE-2008-2489
sg_zfelib < 1.1.512 - SQL Injection
CVE-2008-2491
AbleSpace 1.0 - SQL Injection via cat_id Parameter
CVE-2008-2492
Campus Bulletin Board 3.4 - SQL Injection via id or review Parameter
CVE-2008-2498
Mambo < 4.6.4 - SQL Injection via articleid or mcname Parameter
CVE-2008-2443
The Real Estate Script - SQL Injection via docID Parameter
CVE-2008-2444
CaLogic Calendars 1.2.2 - SQL Injection via langsel Parameter
CVE-2008-2446
Web Group Communication Center < 1.0.3_prerelease1 - Authenticated SQL Injection via Multiple Parameters
CVE-2008-2447
Mytipper ZoGo-shop 1.15.5 and 1.16 Beta 13 - SQL Injection via cat Parameter
CVE-2008-2448
Meto Forum 1.1 - SQL Injection via Multiple Parameters
CVE-2008-2451
inmedias statistics < 0.1.2 - SQL Injection
CVE-2008-2453
PHP Classifieds Script - SQL Injection via fatherID Parameter
CVE-2008-2454
Joomla com_xsstream-dm 0.01 Beta - SQL Injection via Movie Parameter
CVE-2008-2455
e107_blog_engine 2.2 - SQL Injection via rid Parameter
CVE-2008-2456
ComicShout < 2.5 - SQL Injection via comic_id Parameter
CVE-2008-2457
bitmixsoft php-jokesite 2.0 - SQL Injection via cat_id Parameter
CVE-2008-2460
vBulletin 3.7.0 Gold - SQL Injection via FAQ Search Parameter
CVE-2008-2461
Netious CMS 0.4 - SQL Injection via Pageid Parameter
CVE-2008-2422
Webslider - SQL Injection
CVE-2008-2425
FicHive 1.0 - SQL Injection via Search Letter Parameter
CVE-2008-2411
SazCart < 1.5 - SQL Injection via prodid Parameter
Details
Vulnerabilities 19,971
Exploit Likelihood High