CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,971 vulnerabilities with CWE-89
CVE-2008-2412
ACGV News 0.9.1 - SQL Injection via glossaire.php id Parameter
CVE-2008-2416
FicHive 1.0 - SQL Injection via Category Parameter
CVE-2008-2417
How2ASP.net Webboard 4.1 - SQL Injection via qNo Parameter
CVE-2008-2393
EntertainmentScript 1.4.0 - SQL Injection via play.php id Parameter
CVE-2008-2394
TAGWORX.CMS 3.00.02 - SQL Injection via cid or nid Parameter
CVE-2008-2395
AlkalinePHP < 0.80.00 - SQL Injection via Thread ID Parameter
CVE-2008-2351
CMS WebManager-Pro - SQL Injection via lang_id or menu_id Parameters
CVE-2008-2356
Archangel Weblog < 0.90.02 - SQL Injection via post_id Parameter
CVE-2008-2334
Philboard 0.5 - SQL Injection via Multiple Parameters
CVE-2008-2336
68 Classifieds 4.0.1 - SQL Injection via Category Parameter
CVE-2008-2337
IMGallery 2.5 - SQL Injection via kategoria or id_phot Parameter
CVE-2008-2339
Turnkey Web Tools SunShop Shopping Cart 3.5.1 - SQL Injection via index.php id Parameter
CVE-2008-2340
News Manager 2.0 - SQL Injection via lang or pid Parameter
CVE-2008-2286
Symantec Altiris Deployment Solution 6.8.x-6.9.x - SQL Injection via Notification Packet String Fields
CVE-2008-2301
Kostenloses Linkmanagementscript - SQL Injection via id Parameter
CVE-2008-2263
Automated Link Exchange Portal - SQL Injection via cat_id Parameter
CVE-2008-2265
EMO Realty Manager - SQL Injection via news.php ida Parameter
CVE-2008-2277
Feedback and Rating Script 1.0 - SQL Injection via detail.php listingid Parameter
CVE-2008-2278
Freelance Auction Script 1.0 - SQL Injection via browseproject.php pid Parameter
CVE-2008-2222
EQdkp 1.3.2f - SQL Injection via user_id Parameter
CVE-2008-2223
vShare YouTube Clone 2.6 - SQL Injection via tid Parameter
CVE-2008-2225
gameCMS Lite 1.0 - SQL Injection via systemId Parameter
CVE-2008-2189
AnServ Auction XL - SQL Injection via viewfaqs.php cat Parameter
CVE-2008-2190
Online Rent Property Script <= 5.0 - SQL Injection via pid Parameter
CVE-2008-2191
pnEncyclopedia < 0.2.0 - SQL Injection via id Parameter
Details
Vulnerabilities 19,971
Exploit Likelihood High