CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2011-0646
PHP LOW BIDS - SQL Injection via viewfaqs.php cat Parameter
CVE-2011-0645
PHPCMS 2008 V2 - SQL Injection via where_time Parameter
CVE-2011-0644
PHPCMS 2008 V2 - SQL Injection via modelid Parameter
CVE-2011-0519
Gallarific PHP Photo Gallery script 2.1 - SQL Injection via gallery.php id Parameter
CVE-2011-0516
E-PROMPT C BetMore Site Suite 4.0-4.2.0 - SQL Injection via bid Parameter
CVE-2011-0512
Teams Structure module 3.0 - SQL Injection via team_id Parameter
CVE-2011-0511
com_allcinevid 1.0.0 - SQL Injection via id Parameter
CVE-2011-0510
Advanced Webhost Billing System < 2.9.2 - SQL Injection via cart.php oid Parameter
CVE-2011-0443
tinybb 1.2 - SQL Injection via id Parameter in Profile Action
CVE-2011-0407
Phenotype CMS 3.0 - SQL Injection via Crafted URI
CVE-2010-10009
MEDIUM
ptome < 2010-01-11 - SQL Injection
CVSS 5.5
CVE-2010-10007
MEDIUM
lierdakil click-reminder - SQL Injection
CVSS 5.5
CVE-2010-10003
MEDIUM
gesellix titlelink < 2010-08-08 - SQL Injection via Phrase Argument
CVSS 5.5
CVE-2010-3662
HIGH
TYPO3 < 4.1.14, 4.2.x < 4.2.13, 4.3.x < 4.3.4, 4.4.x < 4.4.1 - SQL Injection
CVSS 8.8
CVE-2010-5317
SweetRice CMS <0.6.7.1 - SQL Injection
CVE-2010-5287
Cornerstone Technologies webConductor - SQL Injection
CVE-2010-5063
Virtual War <1.6.1 R2 - SQL Injection
CVE-2010-4824
SilverStripe <2.3.10-2.4.4 - SQL Injection
CVE-2010-5096
MyBB < 1.6.1 - SQL Injection via Search or Private Keywords Parameter
CVE-2010-5103
TYPO3 <4.2.16-4.4.5 - SQL Injection
CVE-2010-5083
PHP-Nuke Web_Links Module - SQL Injection via URL Parameter
CVE-2010-5062
MH Products kleinanzeigenmarkt - SQL Injection
CVE-2010-5061
RSStatic - SQL Injection via maxarticles Parameter
CVE-2010-5060
NUs Newssystem <1.02 - SQL Injection
CVE-2010-5059
CMScout 2.0.8 - SQL Injection via Album Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High