CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-4945
Joomla! com_camelcitydb2 2.2 - SQL Injection
CVE-2010-4944
Mambo/Joomla! - com_elite_experts - SQL Injection
CVE-2010-4942
E-Xoopport Samsara <3.1 - SQL Injection
CVE-2010-4941
com_teams 1_1028_100809_1711 - SQL Injection via PlayerID Parameter
CVE-2010-4940
WAnewsletter 2.1.2 - SQL Injection via id Parameter
CVE-2010-4938
Joomla! com_weblinks - SQL Injection via Itemid Parameter
CVE-2010-4937
Amblog 1.0 for Joomla! - SQL Injection via articleid or catid Parameter
CVE-2010-4936
com_slideshow - SQL Injection via catid Parameter
CVE-2010-4935
Entrans < 0.3.2 - SQL Injection via Poll SID Parameter
CVE-2010-4934
Get Tube < 4.51 - SQL Injection via video.php id Parameter
CVE-2010-4933
Geeklog 1.3.8 - SQL Injection via lid Parameter
CVE-2010-4929
Joostina (com_ezautos) - SQL Injection
CVE-2010-4927
Joomla! com_restaurantguide 1.0.0 - SQL Injection
CVE-2010-4926
com_timetrack 1.2.4 - SQL Injection via ct_id Parameter
CVE-2010-4925
Nuked-Klan Partenaires 1.5 - SQL Injection
CVE-2010-4923
Virtue Netz Virtue Book Store - SQL Injection
CVE-2010-4922
Allinta CMS 22.07.2010 - SQL Injection
CVE-2010-4921
DMXReady Polling Booth Manager - SQL Injection
CVE-2010-4920
Micronetsoft Rental Property Mgmt <1.0 - SQL Injection
CVE-2010-4919
Micronetsoft RV Dealer Website 1.0 - SQL Injection
CVE-2010-4917
A-Blog 2.0 - SQL Injection via Search Words Parameter
CVE-2010-4916
ColdGen ColdUserGroup 1.06 - SQL Injection
CVE-2010-4915
ColdGen ColdBookmarks 1.22 - SQL Injection
CVE-2010-4912
UCenter Home 2.0 - SQL Injection via shop.php shopid Parameter
CVE-2010-4911
PHP Classifieds Ads - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High