CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2014-10038
domphp < 0.83 - SQL Injection via agenda/indexdate.php ids Parameter
CVE-2014-10034
couponphp < 1.1.0 - Authenticated SQL Injection via iDisplayLength or iDisplayStart Parameter
CVE-2014-10033
osCommerce Online Merchant < 2.3.3.4 - Authenticated SQL Injection via zID Parameter
CVE-2014-10032
Taboada MacroNews 1.0 - Authenticated SQL Injection via news_popup.php id Parameter
CVE-2014-100035
LicensePal ArcticDesk < 1.2.4 - SQL Injection in Ticket Grid
CVE-2014-100031
Ganesha Digital Library 4.2 - SQL Injection via id Parameter
CVE-2014-100022
mTouch Quiz < 3.0.6 - SQL Injection via Quiz Parameter
CVE-2014-100020
iTechClassifieds 3.03.057 - SQL Injection via ChangeEmail.php PreviewNum Parameter
CVE-2014-100019
pomm < 1.1.4 - SQL Injection in LTree Converter
CVE-2014-100012
Sendy 1.1.8.4 - SQL Injection via i Parameter
CVE-2014-100011
Sendy 1.1.9.1 - SQL Injection via Send-To c Parameter
CVE-2014-10029
FluxBB < 1.4.13 and 1.5.x < 1.5.7 - SQL Injection via req_new_email Parameter
CVE-2014-10023
TopicsViewer 3.0 Beta 1 - SQL Injection via id Parameter
CVE-2014-10020
Simple e-document 1.31 - SQL Injection via Username Parameter
CVE-2014-10017
Welcart e-Commerce 1.3.12 - SQL Injection via changeSort or switch Parameter
CVE-2014-10015
PHPJabbers Event Booking Calendar 2.0 - SQL Injection via cid Parameter
CVE-2014-10013
Another WordPress Classifieds Plugin - SQL Injection via keywordphrase Parameter
CVE-2014-10004
Maian Uploader 4.0 - SQL Injection via id Parameter
CVE-2014-100003
YourMembers - SQL Injection via ym_download_id Parameter
CVE-2014-2839
GD Star Rating 19.22 - Authenticated SQL Injection via s Parameter
CVE-2014-9528
HumHub <0.10.0-rc.1 - SQL Injection
CVE-2014-9520
InfiniteWP Admin Panel <2.4.4 - SQL Injection
CVE-2014-9519
InfiniteWP Admin Panel <2.4.3 - SQL Injection
CVE-2014-8083
Osclass < 3.4.2 - SQL Injection via Search Alert Subscription Parameter
CVE-2014-9464
Microweber CMS <20141209 - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High