CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,991 vulnerabilities with CWE-89
CVE-2007-6128
WorkingOnWeb 2.0.1400 - SQL Injection
CVE-2007-6106
AlstraSoft E-Friends <4.98 - SQL Injection
CVE-2007-6083
IceBB 1.0-rc6 - SQL Injection via X-Forwarded-For HTTP Header
CVE-2007-6084
HotScripts Clone Script - SQL Injection
CVE-2007-6091
JiRo's Banner System/JUS 2.0 - SQL Injection
CVE-2007-6078
SkyPortal RC6 - SQL Injection via Multiple Parameters
CVE-2007-6080
bcoos 1.0.10 and 1.0.13 - SQL Injection via bid Parameter
CVE-2007-6058
ProfileCMS <= 1.0 - SQL Injection via id Parameter
CVE-2007-6035
Cacti < 0.8.7 - SQL Injection via local_graph_id Parameter
CVE-2007-6032
Aleris Web Publishing Server 3.0 - SQL Injection
CVE-2007-6012
DocuSafe 4.1.0-4.1.2 - SQL Injection
CVE-2007-5991
ExoPHPdesk - SQL Injection via User Parameter in Profile Action
CVE-2007-5992
datecomm Social Networking Script - SQL Injection
CVE-2007-5996
Softbiz Link Directory Script - SQL Injection
CVE-2007-5997
Softbiz Banner Exchange Network Script 1.0 - SQL Injection
CVE-2007-5998
Softbiz Ad Management plus Script 1 - SQL Injection
CVE-2007-5999
Softbiz Auctions Script - SQL Injection
CVE-2007-6004
Toko Instan 7.6 - SQL Injection via id or katid Parameter
CVE-2007-5973
JPortal Web Portal < 2.3.1 - SQL Injection via Topic Parameter
CVE-2007-5974
JPortal 2 - SQL Injection via Mailer to Parameter
CVE-2007-5975
TorrentStrike 0.4 - Authenticated SQL Injection via Choice Parameter
CVE-2007-5976
phpMyAdmin <2.11.2.1 - SQL Injection
CVE-2007-5978
XOOPS mylinks_module - SQL Injection via brokenlink.php lid Parameter
CVE-2007-5986
BtiTracker < 1.4.5 - SQL Injection
CVE-2007-5951
E-Vendejo 0.2 - SQL Injection via articles.php id Parameter
Details
Vulnerabilities 19,991
Exploit Likelihood High