CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2011-5308
cdnvote < 0.4.1 - SQL Injection via cdnvote_post_id or cdnvote_point Parameter
CVE-2011-5286
Social Slider < 7.4.0 - SQL Injection via rA Array Parameter
CVE-2011-2944
The Uploader < 2.0.4 - SQL Injection via Username Parameter
CVE-2011-4970
LCG Disk Pool Manager < 1.8.6 - SQL Injection via Multiple Function Parameters
CVE-2011-5278
Advanced Forum Signatures 2.0.4 - SQL Injection via afs_bar_right Parameter
CVE-2011-5277
Advanced Forum Signatures 2.0.4 - SQL Injection via Multiple Parameters
CVE-2011-5276
Domain Technologie Control < 0.32.11 - Authenticated SQL Injection via database_name Parameter
CVE-2011-5272
Domain Technologie Control < 0.34.1 - Authenticated SQL Injection via vps_note Parameter
CVE-2011-3197
Domain Technologie Control < 0.34.1 - Authenticated SQL Injection via addrlink Parameter
CVE-2011-5262
SonicWALL Aventail SRA EX - SQL Injection via prodpage.cfm CategoryID Parameter
CVE-2011-5259
OrangeHRM < 2.6.11.2 - SQL Injection via CentralController id Parameter
CVE-2011-5235
mnogosearch < 3.3.12 - SQL Injection via Hostname in Hypertext Link
CVE-2011-5234
Social Network Community 2 - SQL Injection via userId Parameter
CVE-2011-5230
Seotoaster < 1.9 - SQL Injection via Login or Member Login Parameter
CVE-2011-5229
appRain CMF 0.1.5 - SQL Injection via PATH_INFO in Forum Module
CVE-2011-5224
Sentinel 1.0.0 - SQL Injection
CVE-2011-5222
PHP Flirt-Projekt 4.8 - SQL Injection via rub Parameter
CVE-2011-5218
DotA OpenStats <= 1.3.9 - SQL Injection via Index.php ID Parameter
CVE-2011-5216
SCORM Cloud For WordPress < 1.0.7 - SQL Injection via Active Parameter
CVE-2011-5215
Video Community Portal - SQL Injection via id Parameter
CVE-2011-5213
BrowserCRM < 5.100.01 - SQL Injection via login[username] or parent_id or contact_id Parameter
CVE-2011-5212
Subrion CMS 2.0.4 - SQL Injection via Admin Login Fields
CVE-2011-4638
SpamTitan WebTitan < 3.50 - SQL Injection via Login Username Parameter
CVE-2011-5203
Akiva WebBoard < 8.0 - SQL Injection via WB/Default.asp Name Parameter
CVE-2011-5201
tinyguestbook - SQL Injection via Name or Message Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High