CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

19,999 vulnerabilities with CWE-89
CVE-2007-5131
Interspire ActiveKB NX 2.x - SQL Injection via catId Parameter
CVE-2007-5122
SoftBiz Classifieds PLUS - SQL Injection via store_info.php id Parameter
CVE-2007-5123
Novus 1.0 - SQL Injection via nota_id Parameter
CVE-2007-5104
bcoos 1.0.10 - SQL Injection via Arcade Module gid Parameter
CVE-2007-5068
phpFullAnnu 6.0 - SQL Injection via mod Parameter
CVE-2007-5061
Clansphere 2007.4 - SQL Injection via cat_id Parameter
CVE-2007-5016
OneCMS 2.4 - SQL Injection via userreviews.php abc Parameter
CVE-2007-4984
Ktauber StylesDemo - SQL Injection via s Parameter
CVE-2007-4979
KwsPHP 1.0 - SQL Injection via Sondages Module id Parameter
CVE-2007-4966
GForge < 4.6_b2 - SQL Injection via skill_delete[] Parameter
CVE-2007-4952
OmniStar Article Manager - SQL Injection via Page ID Parameter
CVE-2007-4953
SimpCMS - SQL Injection via Search Keyword Parameter
CVE-2007-4956
KwsPHP 1.0 - SQL Injection via pseudo Parameter
CVE-2007-4918
Gelatocms - SQL Injection
CVE-2007-4919
JBlog 1.0 - SQL Injection via id Parameter
CVE-2007-4920
PHP Webquest < 2.5 - SQL Injection via id_actividad Parameter
CVE-2007-4922
jeuxflash_module 1.0 - Authenticated SQL Injection via id Parameter
CVE-2007-4892
Plesk 7.6.1, 8.1.0, 8.1.1, 8.2.0 - SQL Injection via PLESKSESSID Cookie
CVE-2007-4894
WordPress < 2.2.3 and WordPress MU < 1.2.5a - SQL Injection via XMLRPC Pingback Post Type Parameter
CVE-2007-4881
psi-labs social networking script (psisns) - SQL Injection via profile/myprofile.php u Parameter
CVE-2007-4845
rw_download_lite 2.0.3 - SQL Injection via dlid or cid Parameter
CVE-2007-4846
Webace-Linkscript 1.3 SE - SQL Injection via start.php id Parameter
CVE-2007-4835
phpMyQuote 0.20 - SQL Injection via id Parameter in Edit Action
CVE-2007-4837
Proxy Anket 3.0.1 - SQL Injection via id Parameter
CVE-2007-4804
AuraCMS 1.5rc - SQL Injection via id Parameter
Details
Vulnerabilities 19,999
Exploit Likelihood High