CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2012-4240
Group-Office < 4.0.90 - Authenticated SQL Injection via Calendar Sort Parameter
CVE-2012-6654
ZPanel < 10.0.1 - SQL Injection via Resetkey or inConfEmail Parameter
CVE-2012-5685
ZPanel < 10.0.1 - SQL Injection via inEmailAddress Parameter
CVE-2012-3820
Campaign Enterprise < 11.0.538 - SQL Injection via SerialNumber or UID Parameter
CVE-2012-0939
TestLink <= 1.8.5b - Authenticated SQL Injection via req_spec_id Parameter
CVE-2012-0938
TestLink <1.9.3, 1.8.5b - SQL Injection
CVE-2012-6643
ClipBucket 2.6 - SQL Injection via Time Parameter
CVE-2012-5648
Foreman < 1.0.2 - SQL Injection via Search Mechanism
CVE-2012-6290
ImageCMS < 4.2 - Authenticated SQL Injection via Admin Search Parameter
CVE-2012-3000
F5 BIG-IP - Authenticated SQL Injection via defaultQuery Parameter
CVE-2012-6626
Brian Cabunac Browser TO Email Phone Message System - SQL Injection
CVE-2012-6625
ForumPress < 1.7.4 - SQL Injection via groupid Parameter
CVE-2012-6588
myre_business_directory - SQL Injection via links.php cat Parameter
CVE-2012-6586
MYRE Vacation Rental Software - SQL Injection via Garage or Bathrooms Parameter
CVE-2012-6584
MYRE Realty Manager - SQL Injection via bathrooms1 Parameter
CVE-2012-5766
IBM Sterling B2B Integrator and Sterling File Gateway - Authenticated SQL Injection via RNVisibility Page
CVE-2012-6144
TYPO3 4.5.0-4.5.20, 4.6.0-4.6.13, 4.7.0-4.7.5 - Authenticated SQL Injection
CVE-2012-6577
Formhandler < 1.4.1 - Authenticated SQL Injection
CVE-2012-6273
BigAnt IM Message Server - SQL Injection via SHU Request
CVE-2012-5760
IBM Netezza WebAdmin 6.0.5, 6.0.8, 7.0 - Authenticated SQL Injection
CVE-2012-6529
Marinet CMS - SQL Injection via id or roomid Parameter
CVE-2012-6526
Vastal I-Tech Freelance Zone - SQL Injection via show_code.php code_id Parameter
CVE-2012-6525
phpbridges - SQL Injection via id Parameter
CVE-2012-6524
powie pGB 2.12 - SQL Injection via kommentar.php id Parameter
CVE-2012-6520
Wikidforum 2.10 - SQL Injection via Advanced Search Parameters
Details
Vulnerabilities
19,915
Exploit Likelihood
High