CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,991 vulnerabilities with CWE-89
CVE-2007-6498
Hosting Controller 6.1-<3 - SQL Injection
CVE-2007-6458
123tkShop 0.9.1 - SQL Injection via Base64-Encoded Admin Parameter
CVE-2007-6462
PHP Real Estate Classifieds - SQL Injection
CVE-2007-6466
FreeWebshop 2.2.1 - SQL Injection via prod/cat/group Parameters
CVE-2007-6467
MKPortal 1.1 RC1 - SQL Injection via ida Parameter in Gallery foto_show Action
CVE-2007-6469
phprpg 0.8 - SQL Injection via Username Parameter
CVE-2007-6391
SH-News 3.0 - SQL Injection via id Parameter
CVE-2007-6392
DWdirectory < 2.1 - SQL Injection via Search Parameter
CVE-2007-6393
Ace Image Hosting Script - SQL Injection
CVE-2007-6394
Content Injector 1.53 - SQL Injection
CVE-2007-6381
TYPO3 3.x 4.0-4.0.7 4.1-4.1.3 - Authenticated SQL Injection
CVE-2007-6338
Trivantis CourseMill <4.1 SP4 - SQL Injection
CVE-2007-6362
RSGallery <2.0 beta 5 - SQL Injection
CVE-2007-6366
SineCMS < 2.3.4 - SQL Injection via Calendar and Guestbook Parameters
CVE-2007-6373
GestDown 1.00 Beta - SQL Injection via categorie or id Parameter
CVE-2007-6375
bitweaver <= 2.0.0 - SQL Injection via sort_mode or highlight Parameter
CVE-2007-6380
e-Xoops 1.08-1.05 Rev 1-3 - SQL Injection
CVE-2007-6345
Aurora Framework <20071208 - SQL Injection
CVE-2007-6342
Apache HTTP Server - AuthCAS 0.4 - SQL Injection
CVE-2007-6318
WordPress <= 2.3.1 - SQL Injection via s Parameter
CVE-2007-6311
Falt4Extreme RC4 10.9.2007 - SQL Injection
CVE-2007-6288
TCExam < 5.1.000 - SQL Injection
CVE-2007-6291
Xigla Absolute Banner Manager .NET 4.0 - SQL Injection
CVE-2007-6292
MWOpen e-commerce 1.4 - SQL Injection via leggi_commenti.asp id Parameter
CVE-2007-6299
Drupal & vbDrupal <4.7.9, 5.x - SQL Injection
Details
Vulnerabilities 19,991
Exploit Likelihood High