CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,973 vulnerabilities with CWE-89
CVE-2008-2087
Softbiz Web Hosting Directory Script - SQL Injection via search_result.php host_id Parameter
CVE-2008-2088
PHP Forge 3.0 beta 2 - SQL Injection via News Module id Parameter
CVE-2008-2083
Prozilla Hosting Index - SQL Injection via cat_id Parameter
CVE-2008-2084
MyArticles 0.6 beta-1 - SQL Injection via topic_id Parameter
CVE-2008-2063
Joovili 3.1 - SQL Injection via Category Parameter
CVE-2008-2065
YourFreeWorld Jokes Site Script - SQL Injection via Jokes.php Catagorie Parameter
CVE-2008-2067
miniBB < 3.0.1 - SQL Injection via whatus Parameter in bb_admin.php
CVE-2008-2047
Angelo-Emlak 1.0 - SQL Injection via id Parameter
CVE-2008-2029
miniBB < 2.2 - SQL Injection via xtr Parameter
CVE-2008-2034
WordPress Download Monitor <2.0.6 - SQL Injection
CVE-2008-2036
dream4 Koobi Pro 6.25 - SQL Injection via poll_id Parameter
CVE-2008-2038
Turnkey Web Tools SunShop Shopping Cart 4.1.0 - SQL Injection
CVE-2008-2023
PD9 Software MegaBBS 2.2 - SQL Injection
CVE-2008-2012
PostNuke PostSchedule 1.0 - SQL Injection
CVE-2008-2013
pnflashgames 1.5-2.5 - SQL Injection via id Parameter
CVE-2008-1990
Acidcat CMS 3.4.1 - SQL Injection via cID or Username Parameter
CVE-2008-1982
Spreadsheet (wpSS) <0.6 - SQL Injection
CVE-2008-1975
cogites e_reserve 2.1 - SQL Injection via ID_loc Parameter
CVE-2008-1968
Cezanne 7 - Authenticated SQL Injection via FUNID Parameter
CVE-2008-1954
Web Calendar Pro <4.1 - SQL Injection
CVE-2008-1957
Tr Script News 2.1 - SQL Injection via nb Parameter in news.php
CVE-2008-1961
Voice Of Web AllMyGuests 0.4.1 - SQL Injection
CVE-2008-1934
Crazy Goomba 1.2.1 - SQL Injection via commentaires.php id Parameter
CVE-2008-1935
Joomla Filiale 1.0.4 - SQL Injection via idFiliale Parameter
CVE-2008-1936
Classifieds Caffe - SQL Injection via cat_id Parameter
Details
Vulnerabilities 19,973
Exploit Likelihood High