CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
20,371 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 10 of 408
- CVE-2007-6667MEDIUMCVSS v2 6.8EG 6.82008-01-04
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413.
- CVE-2007-6670HIGHCVSS v2 7.5EG 7.52008-01-08
SQL injection vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to execute arbitrary SQL commands via the string parameter.
- CVE-2007-6671HIGHCVSS v2 7.5EG 7.52008-01-08
SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Password parameter, a different product than CVE-2006-6021. NOTE: some of these details are ob…
- CVE-2007-6719HIGHCVSS v2 7.5EG 7.52008-12-05
SQL injection vulnerability in Wiz-Ad 1.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVE-2007-6727HIGHCVSS v2 7.5EG 7.52009-07-05
SQL injection vulnerability in topic.php in KerviNet Forum 1.1 allows remote attackers to execute arbitrary SQL commands via the forum parameter.
- CVE-2008-0026MEDIUMCVSS v2 6.5EG 6.52008-02-14
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) a…
- CVE-2008-0089HIGHCVSS v2 7.5EG 7.52008-01-04
SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter.
- CVE-2008-0099MEDIUMCVSS v2 6.8EG 6.82008-01-08
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.
- CVE-2008-0129MEDIUMCVSS v2 6.8EG 6.82008-01-08
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.
- CVE-2008-0130HIGHCVSS v2 7.5EG 7.52008-01-08
SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671. NOTE: the provenance of thi…
- CVE-2008-0133HIGHCVSS v2 7.5EG 7.52008-01-08
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.
- CVE-2008-0137HIGHCVSS v2 7.5EG 7.52008-01-08
PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.
- CVE-2008-0138MEDIUMCVSS v2 6.8EG 6.82008-01-08
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.
- CVE-2008-0139MEDIUMCVSS v2 6.8EG 6.82008-01-08
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.
- CVE-2008-0142MEDIUMCVSS v2 6.8EG 6.82008-01-08
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.
- CVE-2008-0144HIGHCVSS v2 7.5EG 7.52008-01-08
PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged for local file inclusion using direc…
- CVE-2008-0147MEDIUMCVSS v2 6.8EG 6.82008-01-09
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a…
- CVE-2008-0154HIGHCVSS v2 7.5EG 7.52008-01-09
SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.
- CVE-2008-0157HIGHCVSS v2 7.5EG 7.52008-01-09
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.
- CVE-2008-0159MEDIUMCVSS v2 6.8EG 6.82008-01-09
SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.
- CVE-2008-0173HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.
- CVE-2008-0185HIGHCVSS v2 7.5EG 7.52008-01-09
SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).
- CVE-2008-0187HIGHCVSS v2 7.5EG 7.52008-01-09
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.
- CVE-2008-0219HIGHCVSS v2 7.5EG 7.52008-01-10
SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.
- CVE-2008-0224HIGHCVSS v2 7.5EG 7.52008-01-10
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.
- CVE-2008-0232HIGHCVSS v2 7.5EG 7.52008-01-11
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.
- CVE-2008-0253HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.
- CVE-2008-0254MEDIUMCVSS v2 6.8EG 6.82008-01-15
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.
- CVE-2008-0255HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.
- CVE-2008-0256HIGHCVSS v2 7.5EG 7.52008-01-15
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca p…
- CVE-2008-0262HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.
- CVE-2008-0267HIGHCVSS v2 7.5EG 7.52008-01-15
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators …
- CVE-2008-0270MEDIUMCVSS v2 6.0EG 6.02008-01-15
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.
- CVE-2008-0278MEDIUMCVSS v2 6.0EG 6.02008-01-15
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.
- CVE-2008-0279HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter. NOTE: the categorie parameter might also be affected.
- CVE-2008-0280HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.
- CVE-2008-0281HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.
- CVE-2008-0282HIGHCVSS v2 7.5EG 7.52008-01-15
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.
- CVE-2008-0286HIGHCVSS v2 7.5EG 7.52008-01-16
SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields.
- CVE-2008-0288HIGHCVSS v2 7.5EG 7.52008-01-16
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUs…
- CVE-2008-0290HIGHCVSS v2 7.5EG 7.52008-01-16
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to e…
- CVE-2008-0291HIGHCVSS v2 7.5EG 7.52008-01-16
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.
- CVE-2008-0301HIGHCVSS v2 7.5EG 7.52008-03-11
Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazetteer_edit.php and other unspecified vectors.
- CVE-2008-0325HIGHCVSS v2 7.5EG 7.52008-01-17
SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2008-0326HIGHCVSS v2 7.5EG 7.52008-01-17
SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.
- CVE-2008-0327HIGHCVSS v2 7.5EG 7.52008-01-17
SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2008-0328HIGHCVSS v2 7.5EG 7.52008-01-17
SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2008-0353HIGHCVSS v2 7.5EG 7.52008-01-18
SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter. NOTE: some of these details are obtained from third party info…
- CVE-2008-0355HIGHCVSS v2 7.5EG 7.52008-01-18
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007…
- CVE-2008-0358MEDIUMCVSS v2 6.8EG 6.82008-01-18
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →