CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,991 vulnerabilities with CWE-89
CVE-2007-5912
jPORTAL 2 - SQL Injection via Mailer to Parameter
CVE-2007-5916
phphelpdesk 0.6.16 - SQL Injection via Login Page Parameters
CVE-2007-5766
Oracle E-Business Suite 11 and 12 - SQL Injection via okxLOV.jsp
CVE-2007-5887
ASP Message Board 2.2.1c - SQL Injection
CVE-2007-5836
Amazing Flash AFCommerce - SQL Injection
CVE-2007-4863
SAXON 5.4 - SQL Injection via Template Parameter
CVE-2007-5719
miniBB 2.1 - SQL Injection via Table Parameter
CVE-2007-5704
CodeWidgets.com Online Event Registration Template - SQL Injection via Email Address or Password Field
CVE-2007-5688
Multi-Forums Module 1.3.3 for Invision Power Board and phpBB - SQL Injection via go or cat Parameter
CVE-2007-5679
DeeEmm.com DM CMS 0.7.0.Beta and 0.7.4 - SQL Injection via id Parameter
CVE-2007-5678
phpBasic - SQL Injection via Music Module id Parameter
CVE-2007-5643
Lussumo Vanilla < 1.1.3 - SQL Injection via CategoryID Parameter
CVE-2007-5646
Simple Machines Forum 1.1.3 - SQL Injection via Userspec Parameter
CVE-2007-5630
BBPortalS 1.5.10-2.0 - SQL Injection via tnews.php id Parameter
CVE-2007-5488
Asterisk-Addons < 1.2.7 - SQL Injection via Source/Destination Numbers or SIP URI
CVE-2007-5508
Oracle Database 10.1.0.5 and 10.2.0.3 - Authenticated SQL Injection in CTX_DOC Procedures
CVE-2007-5511
Oracle Database Server - SQL Injection via Workspace Manager FINDRICSET Procedure
CVE-2007-5490
Okul Otomasyon Portal 2.0 - SQL Injection via id Parameter
CVE-2007-5485
KwsPHP mg2 1.0 - SQL Injection via Album Parameter
CVE-2007-5458
KwsPHP Newsletter Module 1.0 - SQL Injection via Newsletter Parameter
CVE-2007-5449
Softbiz Recipes Portal Script - SQL Injection via sbcat_id Parameter
CVE-2007-5452
php-stats 0.1.9.2 - SQL Injection via ip or t Parameter
CVE-2007-5430
Stride CMS 1.0 - SQL Injection via p Parameter or id Parameter or course Parameter or provider Parameter
CVE-2007-5408
cpDynaLinks 1.02 - SQL Injection via Category Parameter
CVE-2007-5371
Modxcms - SQL Injection
Details
Vulnerabilities 19,991
Exploit Likelihood High