CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,973 vulnerabilities with CWE-89
CVE-2008-1840
Coppermine Photo Gallery <1.4.16 - SQL Injection
CVE-2008-1841
Coppermine Photo Gallery <1.4.17 - SQL Injection
CVE-2008-1843
W2B DatingClub - SQL Injection via browse.php age_to Parameter
CVE-2008-1844
W2B phpHotResources - SQL Injection
CVE-2008-1847
CoronaMatrix phpAddressBook <2.11 - SQL Injection
CVE-2008-1788
Prozilla Entertainers <1.1 - SQL Injection
CVE-2008-1789
Prozilla Forum - SQL Injection via Forum Parameter
CVE-2008-1791
My Gaming Ladder <7.5 - SQL Injection
CVE-2008-1774
Pligg CMS 9.9.0 - SQL Injection via Editlink.php ID Parameter
CVE-2008-1758
KwsPHP ConcoursPhoto Module - SQL Injection via C_ID Parameter
CVE-2008-1759
jeuxflash_module for KwsPHP - SQL Injection via cat Parameter
CVE-2008-1763
Blogator-script 0.95 - SQL Injection
CVE-2008-1750
Integry Systems LiveCart <1.1.1 - SQL Injection
CVE-2008-1726
KnowledgeQuest 2.6 - SQL Injection via kqid or username Parameter
CVE-2008-1732
Prediction Football <1.x - SQL Injection
CVE-2008-1733
Joomla! PU Arcade <2.2 - SQL Injection
CVE-2008-1714
FaScript FaPhoto 1.0 - SQL Injection
CVE-2008-1715
AuraCMS < 2.2.1 - SQL Injection via Country Parameter
CVE-2008-1699
Desi Quintans Writer's Block CMS <3.8a - SQL Injection
CVE-2008-1623
Smoothflash <admin_view_image.php - SQL Injection
CVE-2008-1626
eggBlog <4.0.1 - SQL Injection
CVE-2008-1631
CuteFlow 1.5.0 and 2.10.0 - SQL Injection via UserId Parameter
CVE-2008-1632
CuteFlow < 2.10.0 - Authenticated SQL Injection via listid userid fieldid or templateid Parameter
CVE-2008-1639
Neat weblog 0.2 - SQL Injection via articleId Parameter
CVE-2008-1640
JGS-XA JGS-Treffen <2.0.2 - SQL Injection
Details
Vulnerabilities 19,973
Exploit Likelihood High