CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2012-5289
Plogger 1.0 RC1 - SQL Injection via id Parameter
CVE-2012-5288
phpMyDirectory 1.3.3 - SQL Injection
CVE-2012-1603
NextBBS 0.6 - SQL Injection via curstr id or username Parameter
CVE-2012-5227
Peel SHOPPING 2.8 and 2.9 - SQL Injection via TVA ID Parameter
CVE-2012-2684
cumin < 0.1.5444 - SQL Injection via Agent or Object ID
CVE-2012-2998
Trend Micro Control Manager <5.5.0.1823, <6.0.0.1449 - SQL Injection
CVE-2012-5162
OSClass < 2.3.5 - SQL Injection via id Parameter in edit_category_post or enable_category Action
CVE-2012-1116
Joomla! 1.7.x and 2.5.x < 2.5.2 - SQL Injection
CVE-2012-0973
OSClass < 2.3.5 - SQL Injection via sCategory Parameter
CVE-2012-5101
JExtensions JE Poll Component < 1.0 - SQL Injection
CVE-2012-5098
Php-X-Links - SQL Injection via id, cid, or t Parameter
CVE-2012-1626
Date module 6.x-2.x < 6.x-2.8 for Drupal - Authenticated SQL Injection
CVE-2012-1638
Search Autocomplete < 7.x-2.1 - Authenticated SQL Injection
CVE-2012-5000
Witze addon 0.9 - SQL Injection via id Parameter
CVE-2012-4996
rivettracker < 1.03 - SQL Injection via Hash Parameter
CVE-2012-4994
LimeSurvey < 1.91+ - Authenticated SQL Injection via id Parameter
CVE-2012-2105
Timesheet Next Gen 1.5.2 - SQL Injection via Username or Password Parameter
CVE-2012-1656
Multisite Search 6.x-2.2 - Authenticated SQL Injection via Site Table Prefix Field
CVE-2012-3032
Siemens WinCC <7.0 SP3 - SQL Injection
CVE-2012-4927
Limesurvey <1.91+ Build 120224 - SQL Injection
CVE-2012-4925
Img Pals Photo Host 1.0 - SQL Injection
CVE-2012-0747
IBM Maximo Asset Mgmt 6.2-7.5 - SQL Injection
CVE-2012-0728
IBM Maximo Asset Mgmt 7.1-7.5 - SQL Injection
CVE-2012-0727
IBM Maximo Asset Mgmt 7.5 - SQL Injection
CVE-2012-2115
OpenEMR < 4.1.0 - SQL Injection via User Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High