CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,973 vulnerabilities with CWE-89
CVE-2008-1939
W1L3D4 Philboard 1.0 - SQL Injection
CVE-2008-1915
DevWorx BlogWorx 1.0 - SQL Injection
CVE-2008-1918
PHP-Fusion <6.01.14, <6.00.307 - SQL Injection
CVE-2008-1919
YourFreeWorld Apartment Search Script - SQL Injection
CVE-2008-1921
5th Avenue Shopping Cart 1.2 - SQL Injection
CVE-2008-1613
RedDot CMS <7.5.0.48 - SQL Injection
CVE-2008-1907
cpCommerce 1.1.0 - SQL Injection via id_product, id_manufacturer, or id_category Parameter
CVE-2008-1909
PHPKB Knowledge Base 1.5 and 2.0 - SQL Injection via ID Parameter
CVE-2008-1911
1024 CMS 1.4.2 beta and earlier - SQL Injection via cookpass Cookie
CVE-2008-1913
Lasernet CMS <1.5,1.11 - SQL Injection
CVE-2008-1889
XplodPHP AutoTutorials <2.1 - SQL Injection
CVE-2008-1890
Jom Comment 2.0 build 345 - SQL Injection
CVE-2008-1895
Carbon Communities <2.4 - SQL Injection
CVE-2008-1863
Prozilla Cheat Script 2.0 - SQL Injection
CVE-2008-1864
Prozilla Freelancers - SQL Injection
CVE-2008-1867
pixel_motion_blog - SQL Injection via categorie Parameter
CVE-2008-1869
Site Sift Listings - SQL Injection via id Parameter
CVE-2008-1870
PIGMy-SQL <= 1.4.1 - SQL Injection via getdata.php id Parameter
CVE-2008-1871
Scriptsagent.com Links Directory 1.1 - SQL Injection
CVE-2008-1872
Comdev News Publisher 4.1.2 - SQL Injection
CVE-2008-1874
xpoze_pro < 3.05 - Authenticated SQL Injection via reed Parameter
CVE-2008-1875
Terong PHP Photo Gallery 1.0 - SQL Injection
CVE-2008-1858
724Networks 724CMS <4.01 - SQL Injection
CVE-2008-1859
iScripts SocialWare - SQL Injection
CVE-2008-1838
BosClassifieds Classified Ads System 3.0 - SQL Injection
Details
Vulnerabilities 19,973
Exploit Likelihood High