CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,988 vulnerabilities with CWE-89
CVE-2008-0089
ClipShare - SQL Injection via UID Parameter
CVE-2007-10003 MEDIUM
The Hackers Diet Plugin <0.9.6b - SQL Injection
CVSS 6.3
CVE-2007-10002 HIGH
web-cyradm < 07-01-2007 - SQL Injection via login/login_password/LANG Argument
CVSS 7.3
CVE-2007-10001 LOW
web-cyradm - SQL Injection via search.php searchstring Parameter
CVSS 3.5
CVE-2007-6727
KerviNet Forum < 1.1 - SQL Injection via Topic Forum Parameter
CVE-2007-6719
Wiz-Ad 1.3 - SQL Injection
CVE-2007-1899
myWebland myBloggie 2.1.6 - SQL Injection via User ID Parameter
CVE-2007-3652 CRITICAL
Farsi Script FaName 1.0 - SQL Injection via id Parameter
CVSS 9.8
CVE-2007-5402
Layton HelpBox 3.7.1 - SQL Injection via sys_request_id Parameter
CVE-2007-6671
Instant Softwares Dating Site - SQL Injection
CVE-2007-6670
PHCDownload 1.1.0 - SQL Injection via Search String Parameter
CVE-2007-6647
w-agora < 4.2.1 - SQL Injection via Index.php Cat Parameter
CVE-2007-6656
CMS Made Simple <1.2.2 - SQL Injection
CVE-2007-6658
CustomCMS CCMS 3.1 Demo - SQL Injection
CVE-2007-6663
Pragmatic Utopia PU Arcade <2.1.3 - SQL Injection
CVE-2007-6664
WebPortal CMS <0.6.0 - SQL Injection
CVE-2007-6665
Netchemia oneSCHOOL - SQL Injection
CVE-2007-6666
Zenphoto 1.1-1.1.3 - SQL Injection via rss.php albumnr Parameter
CVE-2007-6667
MyPHP Forum < 3.0 - SQL Injection via FAQ ID Parameter
CVE-2007-6639
IPTBB 0.5.4 - SQL Injection via id Parameter in viewdir Action
CVE-2007-6622
ZeusCMS < 0.3 - SQL Injection via Referer HTTP Header
CVE-2007-6634
FAQMasterFlexPlus <1.5-1.52 - SQL Injection
CVE-2007-6602
noserub < 0.5.2 - SQL Injection via Login Username Field
CVE-2007-6565
Blakord Portal <1.3.A - SQL Injection
CVE-2007-6566
XZero Community Classifieds <4.95.11 - SQL Injection
Details
Vulnerabilities 19,988
Exploit Likelihood High