CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

20,009 vulnerabilities with CWE-89
CVE-2006-5242
Etomite < 0.6.1 - SQL Injection
CVE-2006-5221
Cahier de texte 2.0 - SQL Injection via matiere_ID or classe_ID Parameter
CVE-2006-4785
moodle < 1.6.1 - SQL Injection via Blog Format Parameter
CVE-2006-4734
Tikiwiki 1.9.4 - SQL Injection via pid or where Parameter
CVE-2006-4736
CMS.R. 5.5 - SQL Injection via adminname or adminpass Parameter
CVE-2006-4756
phpMyDirectory <10.4.6 - SQL Injection
CVE-2006-4564
Simplemachines Smf - SQL Injection
CVE-2006-4214
Zen Cart < 1.3.0.2 - SQL Injection via GPC Data and Session ID
CVE-2006-4064
YenerTurk Haber Script <= 2.0 - SQL Injection via id Parameter
CVE-2006-4042
mybloggie < 2.1.4 - SQL Injection via trackback.php Parameters
CVE-2006-4039
GaesteChaos < 0.2 - SQL Injection via Gastname, Gastwohnort, or Gasteintrag Parameters
CVE-2006-4010
Virtual War <= 1.5.0 - SQL Injection via Page Parameter
CVE-2006-3960
X-Scripts X-Poll - SQL Injection via Poll Parameter
CVE-2006-3904
Etomite < 0.6.1 - SQL Injection via Username Parameter
CVE-2006-3823
GeodesicSolutions GeoAuctions Premier and GeoClassifieds Basic 2.0.3 - SQL Injection via Index.php b Parameter
CVE-2006-3775
Mybulletinboard - SQL Injection
CVE-2006-3688
Francisco Charrua Photo-Gallery 1.0 - SQL Injection via Room.php id Parameter
CVE-2006-3430
PatchLink Update Server < 6.1 P1 and 6.2.x < 6.2 SR1 P1 - SQL Injection via agentid Parameter
CVE-2006-3318
phpRaid 3.0.6 - SQL Injection via Username or Email Parameter
CVE-2006-3181
MobeScripts Mobile Space Community 2.0 - SQL Injection
CVE-2006-3139
Virtual War <1.5.0 R14 - SQL Injection
CVE-2006-3064
Coppermine Photo Gallery <1.4.8 - SQL Injection
CVE-2006-3048
TikiWiki < 1.9.3.1 - SQL Injection
CVE-2006-2973
PHP Lite Calendar Express 2.2 - SQL Injection
CVE-2006-2977
Mafia Moblog <0.6M1 - SQL Injection
Details
Vulnerabilities 20,009
Exploit Likelihood High