CWE-89— SQL Injection
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.— MITRE CWE catalog
18,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-89page 43 of 379
- CVE-2009-1734HIGHCVSS v2 7.5EG 7.52009-05-20
SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter.
- CVE-2009-1736HIGHCVSS v2 7.5EG 7.52009-05-20
SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php.
- CVE-2009-1741MEDIUMCVSS v2 6.8EG 6.82009-05-20
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
- CVE-2009-1742HIGHCVSS v2 7.5EG 7.52009-05-20
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via …
- CVE-2009-1746HIGHCVSS v2 7.5EG 7.52009-05-21
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
- CVE-2009-1747HIGHCVSS v2 7.5EG 7.52009-05-22
SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action.
- CVE-2009-1751HIGHCVSS v2 7.5EG 7.52009-05-22
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2009-1764HIGHCVSS v2 7.5EG 7.52009-05-22
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action.
- CVE-2009-1766MEDIUMCVSS v2 6.4EG 6.42009-05-22
SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2009-1778MEDIUMCVSS v2 6.8EG 6.82009-05-22
SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
- CVE-2009-1787HIGHCVSS v2 7.5EG 7.52009-05-26
Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.
- CVE-2009-1799MEDIUMCVSS v2 6.8EG 6.82009-05-28
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_…
- CVE-2009-1804HIGHCVSS v2 7.5EG 7.52009-05-28
Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
- CVE-2009-1810MEDIUMCVSS v2 6.0EG 6.02009-05-29
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbit…
- CVE-2009-1812MEDIUMCVSS v2 6.0EG 6.02009-05-29
Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to e…
- CVE-2009-1813HIGHCVSS v2 7.5EG 7.52009-05-29
Multiple SQL injection vulnerabilities in admin/index.php in Submitter Script 2 allow remote attackers to execute arbitrary SQL commands via (1) the uNev parameter (aka the username field) or (2) the uJelszo parameter (aka the Password fie…
- CVE-2009-1814HIGHCVSS v2 7.5EG 7.52009-05-29
SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.
- CVE-2009-1816HIGHCVSS v2 7.5EG 7.52009-05-29
SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the username field). NOTE: some of these details are obtained from third party informatio…
- CVE-2009-1818HIGHCVSS v2 7.5EG 7.52009-05-29
SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via an m_username cookie in an add action.
- CVE-2009-1819HIGHCVSS v2 7.5EG 7.52009-05-29
SQL injection vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2009-1842HIGHCVSS v2 7.5EG 7.52009-06-01
SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
- CVE-2009-1843HIGHCVSS v2 7.5EG 7.52009-06-01
Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) quiz parameter to (a) num_questions.php, (b) answers.php, (c) high_score.php, (d) high_score_web.php, (e) resu…
- CVE-2009-1848HIGHCVSS v2 7.5EG 7.52009-06-01
SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a groupdetail action to index.php.
- CVE-2009-1850HIGHCVSS v2 7.5EG 7.52009-06-01
SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL commands via the password parameter.
- CVE-2009-1851HIGHCVSS v2 7.5EG 7.52009-06-01
SQL injection vulnerability in include.php in phpBugTracker 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtai…
- CVE-2009-1852HIGHCVSS v2 7.5EG 7.52009-06-01
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
- CVE-2009-1853HIGHCVSS v2 7.5EG 7.52009-06-01
Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action.
- CVE-2009-1909HIGHCVSS v2 7.5EG 7.52009-06-04
SQL injection vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVE-2009-1910HIGHCVSS v2 7.5EG 7.52009-06-04
SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands via the AlbumId parameter.
- CVE-2009-1913MEDIUMCVSS v2 5.1EG 5.12009-06-04
SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authentication is used, allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.
- CVE-2009-1945HIGHCVSS v2 7.5EG 7.52009-06-05
SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
- CVE-2009-1947HIGHCVSS v2 7.5EG 7.52009-06-05
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a …
- CVE-2009-1950HIGHCVSS v2 7.5EG 7.52009-06-05
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL commands via the mesajid parameter.
- CVE-2009-1952MEDIUMCVSS v2 6.8EG 6.82009-06-05
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password param…
- CVE-2009-2004HIGHCVSS v2 7.5EG 7.52009-06-08
Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CV…
- CVE-2009-2008MEDIUMCVSS v2 6.8EG 6.82009-06-08
Multiple SQL injection vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) uInfo parameter to main/tracking/userLog.php and the (2) course parameter to main/mySpace/lp…
- CVE-2009-2010MEDIUMCVSS v2 6.5EG 6.52009-06-08
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter …
- CVE-2009-2013HIGHCVSS v2 7.5EG 7.52009-06-09
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitrary SQL commands via the source_class parameter in a browse_classes action.
- CVE-2009-2014HIGHCVSS v2 7.5EG 7.52009-06-09
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.php.
- CVE-2009-2016HIGHCVSS v2 7.5EG 7.52009-06-09
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter.
- CVE-2009-2017HIGHCVSS v2 7.5EG 7.52009-06-09
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL commands via the cid parameter.
- CVE-2009-2018MEDIUMCVSS v2 6.8EG 6.82009-06-09
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
- CVE-2009-2019HIGHCVSS v2 7.5EG 7.52009-06-09
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
- CVE-2009-2021HIGHCVSS v2 7.5EG 7.52009-06-09
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter.
- CVE-2009-2023MEDIUMCVSS v2 6.8EG 6.82009-06-09
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the current_currency parameter.
- CVE-2009-2034MEDIUMCVSS v2 6.0EG 6.02009-06-12
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.
- CVE-2009-2036HIGHCVSS v2 7.5EG 7.52009-06-12
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
- CVE-2009-2082HIGHCVSS v2 7.5EG 7.52009-06-16
SQL injection vulnerability in insidepage.php in Creative Web Solutions Multi-Level CMS 1.21 allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: some of these details are obtained from third party info…
- CVE-2009-2093MEDIUMCVSS v2 6.5EG 6.52009-08-13
SQL injection vulnerability in the console in IBM WebSphere Partner Gateway (WPG) Enterprise 6.0 before FP8, 6.1 before FP3, 6.1.1 before FP2, and 6.2 before FP1 allows remote authenticated users to execute arbitrary SQL commands via unspe…
- CVE-2009-2096HIGHCVSS v2 7.5EG 7.52009-06-17
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute arbitrary SQL commands via the itemnr parameter.
Map vulnerabilities like CWE-89 to your infrastructure
EchelonGraph correlates every CVE — across CWE-89 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →