CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,973 vulnerabilities with CWE-89
CVE-2008-2190
Online Rent Property Script <= 5.0 - SQL Injection via pid Parameter
CVE-2008-2191
pnEncyclopedia < 0.2.0 - SQL Injection via id Parameter
CVE-2008-2194
deluxebb < 1.1 - SQL Injection via forums.php sort Parameter
CVE-2008-2197
Miniweb2 blog_writer 2.0 - SQL Injection via Historymonth Parameter
CVE-2008-2203
Maian Search 1.1 - SQL Injection via Keywords Parameter
CVE-2008-2205
Maian Music 1.1 - SQL Injection via Album Parameter
CVE-2008-2208
Maian Greeting 2.1 - SQL Injection via Keywords Parameter
CVE-2008-2175
Gamma Scripts BlogMe PHP 1.1 - SQL Injection via id Parameter
CVE-2008-2177
phpDirectorySource 1.1.06 - SQL Injection via lid or login Parameter
CVE-2008-2180
cpLinks 1.03 - SQL Injection via Admin Username or Search Parameters
CVE-2008-2183
SMartBlog 1.3 - SQL Injection via idt Parameter
CVE-2008-2184
SMartBlog 1.3 - SQL Injection via mois an jour id or login Parameters
CVE-2008-2124
fipsASP fipsCMS - SQL Injection via lg Parameter
CVE-2008-2125
Musicbox 2.3.6-2.3.7 - SQL Injection via viewalbums.php artistId Parameter
CVE-2008-2129
Galleristic 1.0 - SQL Injection via Cat Parameter
CVE-2008-2130
iGaming CMS 1.5 - SQL Injection via poll_vote.php id Parameter
CVE-2008-2132
Systementor PostcardMentor - SQL Injection via cat_fldAuto Parameter
CVE-2008-2135
VisualShapers ezContents 2.0.0 - SQL Injection via contentname or article Parameter
CVE-2008-2113
PHPEasyData 1.5.4 - SQL Injection via annuaire.php cat_id Parameter
CVE-2008-2114
Pre Shopping Mall 1.1 - SQL Injection via Search Parameter
CVE-2008-2118
Project Alumni 1.0.9 - SQL Injection via id Parameter
CVE-2008-2096
BackLinkSpider - SQL Injection via cat_id Parameter
CVE-2008-2093
Community Builder for Joomla! and Mambo - SQL Injection via User Parameter
CVE-2008-2094
XOOPS Article Module - SQL Injection via id Parameter
CVE-2008-2095
Joomla com_flippingbook 1.0.4 - SQL Injection via book_id Parameter
Details
Vulnerabilities 19,973
Exploit Likelihood High