CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2012-3468
Ushahidi Platform < 2.5 - SQL Injection via Alerts Verify, Settings Save, or Timeline Media Type
CVE-2012-4070
dir2web 3.0 - SQL Injection via oid Parameter
CVE-2012-4034
PBBoard 2.1.4 - SQL Injection via Multiple Parameters
CVE-2012-3953
phplist < 2.10.19 - Authenticated SQL Injection via Edit Attributes Delete Parameter
CVE-2012-3132
Oracle Database Server <11.2.0.3 - SQL Injection
CVE-2012-3554
RSGallery2 < 2.3.0 for Joomla! 1.5.x and < 3.2.0 for Joomla! 2.5.x - SQL Injection
CVE-2012-4178
Symantec Web Gateway 5.0.3.18 - SQL Injection via groupid Parameter
CVE-2012-3951
Plixer Scrutinizer <= 9.0.1.19899 - Unauthenticated SQL Injection via Default MySQL Credentials
CVE-2012-2962
Plixer Scrutinizer <9.5.2 - SQL Injection
CVE-2012-4061
ASP-DEv XM Diary - SQL Injection via id or view_date Parameter
CVE-2012-4060
ASP-DEv XM Forums RC3 - SQL Injection via id Parameter
CVE-2012-4056
Uiga Personal Portal - SQL Injection via index2.php p Parameter
CVE-2012-4055
Uiga Fan Club - SQL Injection via p Parameter
CVE-2012-2306
Drupal Addressbook module 6.x-4.2 - SQL Injection
CVE-2012-3395
Moodle 2.0.x-2.0.10, 2.1.x-2.1.7, 2.2.x-2.2.4 - Authenticated SQL Injection via Feedback Form Data
CVE-2012-2961
Symantec Web Gateway <5.0.3.18 - SQL Injection
CVE-2012-2574
Symantec Web Gateway <5.0.3.18 - SQL Injection
CVE-2012-2363
Moodle 1.9.x < 1.9.18 - Authenticated SQL Injection via Calendar Event
CVE-2012-0868
PostgreSQL <8.3.18, <8.4.11, <9.0.7, <9.1.3 - SQL Injection
CVE-2012-3998
Sticky Notes < 0.2.27052012.5 - SQL Injection via Paste ID, User ID, Project, or Session ID
CVE-2012-3350
Webmatic 3.1.1 - SQL Injection via Referer HTTP Header
CVE-2012-3881
Adrian Chadd Rtg - SQL Injection
CVE-2012-3839
MyClientBase 0.12 - SQL Injection via Invoice Search Parameters
CVE-2012-3834
AlienVault Open Source Security Information Management 3.1 - Authenticated SQL Injection via time[0][0] Parameter
CVE-2012-2695
Ruby on Rails <3.0.14, <3.1.x <3.1.6, <3.2.x <3.2.6 - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High