← Back
CWE-89

20,587 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

JSON object

Loading...

CVEs (20,587)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Romedchim International Srl
1Online Rent Property Script
Apr 23, 2026
May 14, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it was later reported th...Show more
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it was later reported that 5.0 and earlier are also affected.Show less
1Anserv
1Auction Xl
Apr 23, 2026
May 14, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Toocharger
1Smartblog
Apr 23, 2026
May 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in SMartBlog (aka SMBlog) 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) mois, (2) an, (3) jour, and (4) id parameters to index.php, and the (5) login para...Show more
Multiple SQL injection vulnerabilities in SMartBlog (aka SMBlog) 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) mois, (2) an, (3) jour, and (4) id parameters to index.php, and the (5) login parameter to gestion/logon.php, different vectors than CVE-2008-2183. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Toocharger
1Smartblog
Apr 23, 2026
May 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to execute arbitrary SQL commands via the idt parameter.
1Cplinks
1Cplinks
Apr 23, 2026
May 13, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) admin_username parameter (aka the username field) to admin/i...Show more
Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) admin_username parameter (aka the username field) to admin/index.php and the (2) search_text and (3) search_category parameters to search.php. NOTE: some of these details are obtained from third party information.Show less
1Php Directory Source
1Phpdirectorysource
Apr 23, 2026
May 13, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in phpDirectorySource 1.1.06, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to show.php and the (2) login par...Show more
Multiple SQL injection vulnerabilities in phpDirectorySource 1.1.06, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to show.php and the (2) login parameter to admin.php.Show less
1Gamma Scripts
1Blogme Php
Apr 23, 2026
May 13, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in comments.php in Gamma Scripts BlogMe PHP 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Visualshapers
1Ezcontents
Apr 23, 2026
May 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to prin...Show more
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php.Show less
1Systementor
1Postcardmentor
Apr 23, 2026
May 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in step1.asp in Systementor PostcardMentor allows remote attackers to execute arbitrary SQL commands via the cat_fldAuto parameter.
1Igaming
1Cms
Apr 23, 2026
May 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in poll_vote.php in iGaming CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Cine
1Galleristic
Apr 23, 2026
May 9, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in index.php in Galleristic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.
1Musicbox
1Musicbox
Apr 23, 2026
May 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
1Fipsasp
1Fipscms
Apr 23, 2026
May 9, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter.
1Project Alumni
1Project Alumni
Apr 23, 2026
May 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.
1Preprojects
1Pre Shopping Mall
Apr 23, 2026
May 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
1Phpeasydata
1Phpeasydata
Apr 23, 2026
May 8, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
1Backlinkspider
1Backlink Spider
Apr 23, 2026
May 7, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to a site-specific component name such as link.php or backlinkspider.php.
3Joomla
MamboPage Flip Tools
3Com Flippingbook
Com FlippingbookFlipping Book
Apr 23, 2026
May 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
1Xoops
1Article Module
Apr 23, 2026
May 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
3Joomla
JoomlapolisMambo
3Com Comprofiler
Com ComprofilerCommunity Builder
Apr 23, 2026
May 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action...Show more
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.Show less