CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,987 vulnerabilities with CWE-89
CVE-2008-1344
MyioSoft EasyCalendar <4.0tr - SQL Injection
CVE-2008-1346
MyioSoft EasyGallery <5.0tr - SQL Injection
CVE-2008-1349
bamaGalerie 3.03-3.041 - SQL Injection
CVE-2008-1350
Fully Modded phpBB 80220 - SQL Injection
CVE-2008-1351
XOOPS Tutorials 2.1b - SQL Injection via tid Parameter
CVE-2008-1336
Koobi CMS 4.2.3-4.3.0 - SQL Injection via Categ Parameter
CVE-2008-1315
ZClassifieds - SQL Injection via Cat Parameter
CVE-2008-1316
QT-cute QuickTalk Forum <1.6 - SQL Injection
CVE-2008-1295
phpMyNewsletter <0.8 beta 5 - SQL Injection
CVE-2008-1297
eWriting 1.2.1 - SQL Injection via cat Parameter
CVE-2008-1298
Hadith module for PHP-Nuke - SQL Injection via cat Parameter
CVE-2008-1305
Filebase mod for phpBB - SQL Injection
CVE-2008-1308
Sudirman Angriawan NukeC30 3.0 - SQL Injection
CVE-2008-1313
Bloo < 1.0 - SQL Injection via post_id Parameter
CVE-2008-1314
Johannes Hass gaestebuch 2.2 - SQL Injection
CVE-2008-0301
Mapbender 2.4.4 - SQL Injection via mod_gazetteer_edit.php gaz Parameter
CVE-2008-1272
BM Classifieds <20080309 - SQL Injection
CVE-2008-1219
Kutub-i Sitte <1.1 - SQL Injection
CVE-2008-1220
4nChat 0.91 - SQL Injection via roomid Parameter
CVE-2008-1177
Affiliate Market 0.1 BETA - SQL Injection
CVE-2008-1162
PHP WEB SCRIPT Dynamic Photo Gallery 1.02 - SQL Injection
CVE-2008-1163
phpArcadeScript <3.0 RC2 - SQL Injection
CVE-2008-1164
phpComasy 0.8 - SQL Injection via mod_project_id Parameter
CVE-2008-1149
phpMyAdmin <2.11.5 - CSRF & SQL Injection
CVE-2008-1137
Garys Cookbook <1.1.1 - SQL Injection
Details
Vulnerabilities 19,987
Exploit Likelihood High