CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-4910
ColdGen ColdCalendar <2.06 - SQL Injection
CVE-2010-4908
Virtue Shopping Mall - SQL Injection
CVE-2010-4906
Zenphoto 1.3 and 1.3.1.2 - SQL Injection via a Parameter
CVE-2010-4905
Softbiz Article Directory Script - SQL Injection
CVE-2010-4904
Joomla! com_aardvertiser 2.1-2.1.1 - SQL Injection
CVE-2010-4903
CubeCart 4.3.3 - SQL Injection via searchStr Parameter
CVE-2010-4902
Joomla! com_clantools 1.2.3 - SQL Injection
CVE-2010-4899
CMS WebManager-Pro <8.1 - SQL Injection
CVE-2010-4898
Gantry (com_gantry) 3.0.10 - SQL Injection via moduleid Parameter
CVE-2010-4897
BlueCMS 1.6 - SQL Injection via X-Forwarded-For Header
CVE-2010-4894
chillyCMS 1.1.3 - SQL Injection via Name Parameter
CVE-2010-4891
Yet Another Calendar <1.1.2 - SQL Injection
CVE-2010-4888
TYPO3 hm_tinymarket <0.5.4 - SQL Injection
CVE-2010-4887
TYPO3 commentsbe <0.0.2 - SQL Injection
CVE-2010-4876
mBlogger 1.0.04 - SQL Injection via viewpost.php postID Parameter
CVE-2010-4872
ASPilot Pilot Cart 7.3 - SQL Injection
CVE-2010-4870
BloofoxCMS 0.3.5 - SQL Injection via Gender Parameter
CVE-2010-4869
DBHcms 1.1.4 - SQL Injection via Editmenu Parameter
CVE-2010-4866
chipmunk_board 1.3 - SQL Injection via forumID Parameter
CVE-2010-4865
JE Guestbook (com_jeguestbook) 1.0 - SQL Injection
CVE-2010-4864
Club Manager (com_clubmanager) for Joomla! - SQL Injection via cm_id Parameter
CVE-2010-4862
Joomla! com_jedirectory 1.0 - SQL Injection
CVE-2010-4861
webSPELL 4.2.1 - SQL Injection via asearch.php Search Parameter
CVE-2010-4860
MyPhpAuction 2010 - SQL Injection via product_desc.php id Parameter
CVE-2010-4859
WebAsyst Shop-Script - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High