CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,991 vulnerabilities with CWE-89
CVE-2007-6266
bcoos <= 1.0.10 - SQL Injection via gid Parameter or lid Parameter
CVE-2007-6269
Absolute News Manager.NET 5.1 - SQL Injection
CVE-2007-6272
Joomla! 1.5 RC3 - SQL Injection via com_content or com_search Parameters
CVE-2007-6275
bcoos < 1.0.10 - SQL Injection via lid Parameter
CVE-2007-6014
Beehive Forum <0.7.1 - SQL Injection
CVE-2007-6240
Snitz Forums 2000 3.4.06 - SQL Injection
CVE-2007-6223
phpBB Garage 1.2.0 Beta3 - SQL Injection
CVE-2007-6217
Irola My-Time 3.5 - SQL Injection via Login and Password Parameters
CVE-2007-6202
Neocrome Seditio CMS <121 - SQL Injection
CVE-2007-6170
Asterisk <1.4.15, 1.2.25, B.2.3.4, C.1.0-beta6 - SQL Injection
CVE-2007-6171
Asterisk <1.4.15, C.<C.1.0-beta6 - SQL Injection
CVE-2007-6172
wpQuiz 2.7 - SQL Injection via id Parameter
CVE-2007-6158
Proverbs Web Calendar <1.1 - SQL Injection
CVE-2007-6159
Tilde CMS 4.x and earlier - SQL Injection via aarstal Parameter
CVE-2007-6163
GOUAE DWD Realty - SQL Injection via Password Parameter
CVE-2007-6164
Eurologon CMS - SQL Injection via id Parameter
CVE-2007-6168
VU Case Manager - SQL Injection via Username Parameter
CVE-2007-6169
GOUAE DWD Realty - SQL Injection via uname Parameter
CVE-2007-6134
PHPKIT 1.6.4pl1 - SQL Injection via contentid Parameter
CVE-2007-6137
Content Injector <1.52 - SQL Injection
CVE-2007-6138
VU Mass Mailer - SQL Injection via Login Page Password Parameter
CVE-2007-6140
Dora Emlak 2.0 - SQL Injection via id, kategori, or tip Parameter
CVE-2007-6143
VU Case Manager - SQL Injection via Login Page Password Parameter
CVE-2007-6125
Softbiz Freelancers Script - SQL Injection
CVE-2007-6127
Project Alumni <1.0.9 - SQL Injection
Details
Vulnerabilities 19,991
Exploit Likelihood High