← Back
CWE-89

20,600 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,600)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dotnetindex
1Professional Download Assistant
Apr 23, 2026
Dec 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka p...Show more
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.Show less
1Netref
1Netref
Apr 23, 2026
Dec 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Netref 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) fiche_product.php and (2) presentation.php.
1Dazzlindonna
1Postecards
Apr 23, 2026
Dec 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Pozscripts
1Business Directory Script
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
1Digitalgreys
1Com Contactinfo
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
1Phpstore
2Wholesale
Wholesales
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Slimcms
1Slimcms
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.
1Phpstore
1Yahoo Answers
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Clip Share
1Clipshare
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in channel_detail.php in ClipShare Pro 4, and 2006 through 2007, allows remote attackers to execute arbitrary SQL commands via the chid parameter.
1E Topbiz
1Domain Shop
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.
1Turnkeyforms
1Text Link Sales
Apr 23, 2026
Dec 12, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Punbb
1Punbb
Apr 23, 2026
Dec 11, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in PunBB 1.3 and 1.3.1 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) order_by or (2) direction parameter to admin/users.php, or (3) configu...Show more
Multiple SQL injection vulnerabilities in PunBB 1.3 and 1.3.1 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) order_by or (2) direction parameter to admin/users.php, or (3) configuration options to admin/settings.php.Show less
1Activewebsoftwares
1Activevotes
Apr 23, 2026
Dec 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
1Multimania
2Bandsite Portal System
Bandwebsite
Apr 23, 2026
Dec 5, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Bdigital Web Solutions
1Webstudio Cms
Apr 23, 2026
Dec 5, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via the pageid parameter.
1Php Fusion
1Php Fusion
Apr 23, 2026
Dec 5, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a differ...Show more
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459.Show less
1Nitrotech
1Nitrotech
Apr 23, 2026
Dec 5, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Inspector It
1Wiz Ad
Apr 23, 2026
Dec 5, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Wiz-Ad 1.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third pa...Show more
SQL injection vulnerability in Wiz-Ad 1.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Xoops Hocasi
1Gesgaleri
Apr 23, 2026
Dec 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.
1E107
1E107
Apr 23, 2026
Dec 3, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.