CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,973 vulnerabilities with CWE-89
CVE-2008-1641
EfesTECH Video 5.0 - SQL Injection via catID Parameter
CVE-2008-1644
Sava's Link Manager 2.0 - SQL Injection
CVE-2008-1646
WP-Download 1.2 - SQL Injection via dl_id Parameter
CVE-2008-1650
EasyNews 4.0 - SQL Injection via read Parameter in edp_Help_Internal_News Action
CVE-2008-1607
Serbay Arslanhan Bomba Haber 2.0 - SQL Injection
CVE-2008-1608
Clever Copy 3.0 - SQL Injection via ID Parameter
CVE-2008-1591
PostNuke < 0.764 - SQL Injection via HTTP_CLIENT_IP Variable
CVE-2008-1549
Aeries Browser Interface 3.8.3.14 - SQL Injection
CVE-2008-1551
RunCMS Photo Module 3.02 - SQL Injection via viewcat.php cid Parameter
CVE-2008-1554
TopperMod 2.0 - SQL Injection via Localita Parameter
CVE-2008-1559
Joomla! com_alphacontent 2.5.8 - SQL Injection
CVE-2008-1535
Matti Kiviharju rekry <1.0.0 - SQL Injection
CVE-2008-1539
PHP-Nuke Platinum 7.6.b.5 - SQL Injection
CVE-2008-1540
Joomla! & Mambo com_datsogallery 1.3.1 - SQL Injection
CVE-2008-1508
EfesTech E-Kontr - SQL Injection via id Parameter
CVE-2008-1509
xlportal < 2.2.4 - SQL Injection via Query Parameter
CVE-2008-1513
Danneo CMS < 0.5.1 - SQL Injection via HTTP Referer Header
CVE-2008-1494
Easy-Clanpage 2.2 - SQL Injection via id Parameter in User Details Action
CVE-2008-1496
PEEL - SQL Injection via Email Parameter or Timestamp Parameter
CVE-2008-1486
Phorum < 5.2.6 - SQL Injection via Non-Fulltext Search
CVE-2008-1462
RunCMS - Section Module < SQL Injection
CVE-2008-1464
Gallarific Free Edition 1.1 - SQL Injection
CVE-2008-1465
Detodas Restaurante (com_restaurante) 1.0 - SQL Injection
CVE-2008-1459
com_alberghi 2.1.3 - SQL Injection via id Parameter
CVE-2008-1460
com_joovideo 1.0 and 1.2.2 - SQL Injection via id Parameter
Details
Vulnerabilities 19,973
Exploit Likelihood High