CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
20,010 vulnerabilities with CWE-89
CVE-2003-0845
JBoss 3.0.8 and 3.2.1 - SQL Injection via HSQLDB Component
CVE-2003-0286
Snitz Forums <3.4.03-3.4.07 - SQL Injection
CVE-2003-0377
iisprotect < 2.2 - SQL Injection via GroupName Variable in SiteAdmin.ASP
CVE-2002-2252
thatware < 0.5 - SQL Injection via Base64-Encoded User Parameter
CVE-2002-2277
PortailPHP 0.99 - SQL Injection via mod_search/index.php Parameters
CVE-2002-2304
MyPHPLinks 2.1.9 and 2.2.0 - SQL Injection via idsession Parameter
CVE-2002-2305
phpsecure.org immobilier - SQL Injection via agentname or agentpassword Parameter
CVE-2002-2383
f2html.pl 0.1-0.4 - SQL Injection via File Name Parameter
CVE-2002-2391
WebChat 1.5 - SQL Injection via roomid Parameter
CVE-2002-0999
CARE 2002 - SQL Injection
Details
Vulnerabilities
20,010
Exploit Likelihood
High