CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,988 vulnerabilities with CWE-89
CVE-2008-0692
iTechBids 3 Gold and 5.0 - SQL Injection via bidhistory.php item_id Parameter
CVE-2008-0695
BookmarkX script 2007 - SQL Injection via topicid Parameter
CVE-2008-0649
Astanda Directory Project 1.2-1.3 - SQL Injection via detail.php link_id Parameter
CVE-2008-0650
Simple OS CMS 0.1c beta - SQL Injection via Username Field
CVE-2008-0651
Pedro Santana Codice CMS - SQL Injection via Login Username Field
CVE-2008-0652
Joomla com_downloads - SQL Injection via filecatid Parameter
CVE-2008-0653
Joomla com_ynews 1.0.0 - SQL Injection via id Parameter
CVE-2008-0601
All Club CMS < 0.0.1f - SQL Injection via Name Parameter
CVE-2008-0603
amazOOP Awesom! 0.3.2 - SQL Injection via listid Parameter
CVE-2008-0606
Joomla com_shambo2 - SQL Injection via Itemid Parameter
CVE-2008-0607
Sigsiu Online Business Index 2 (SOBI2) 2.5.3 - SQL Injection via catid Parameter
CVE-2008-0611
RMSOFT Gallery System 2.0 - SQL Injection via id Parameter
CVE-2008-0614
Photokorn Gallery 1.543 - SQL Injection via Pic Parameter
CVE-2008-0616
DMSGuestbook 1.7.0 - Authenticated SQL Injection
CVE-2008-0579
Joomla com_buslicense - SQL Injection via aid Parameter
CVE-2008-0565
DeltaScripts PHP Links < 1.3 - SQL Injection via vote.php id Parameter
CVE-2008-0557
CatalogShop 1.0b1 - SQL Injection via id Parameter
CVE-2008-0561
Arthur Konze AkoGallery 2.5 beta - SQL Injection via id Parameter
CVE-2008-0562
Joomla Restaurant Component 1.0 - SQL Injection via id Parameter
CVE-2008-0538
phpIP Management 4.3.2 - SQL Injection via Password and ID Parameters
CVE-2008-0543
Pre Dynamic Institution - SQL Injection via sloginid or spass Parameter
CVE-2008-0546
CandyPress 4.1.1.26 - SQL Injection via idProduct or options Parameter
CVE-2008-0504
Coppermine Photo Gallery < 1.4.15 - Authenticated SQL Injection via Album Parameters
CVE-2008-0507
AdServe 0.2 - SQL Injection via id Parameter
CVE-2008-0510
Joomla! and Mambo Newsletter Component - SQL Injection via listid Parameter
Details
Vulnerabilities 19,988
Exploit Likelihood High