CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-4700
PHP 5.3.2-5.3.3 - SQL Injection via set_magic_quotes_runtime and mysqli_fetch_assoc Interaction
CVE-2010-4696
Joomla! 1.5.x < 1.5.22 - SQL Injection via filter_order or filter_order_Dir Parameter
CVE-2010-4166
Joomla! < 1.5.22 - SQL Injection via filter_order or filter_order_Dir Parameter
CVE-2010-0115
Symantec Web Gateway < 4.5.0.376 - SQL Injection via USERNAME Parameter
CVE-2010-3924
Aimluck Aipo < 5.1 - Authenticated SQL Injection
CVE-2010-4496
TIBCO Collaborative Information Manager < 8.0 and ActiveCatalog < 1.0 - SQL Injection
CVE-2010-4641
XWiki Enterprise < 2.5 - SQL Injection
CVE-2010-4639
MySource Matrix - SQL Injection via id Parameter
CVE-2010-4638
com_jquarks4s 1.0.0 - SQL Injection via submitSurvey q Parameter
CVE-2010-4636
Site2Nite Business e-Listings - SQL Injection via ID Parameter
CVE-2010-4635
Site2Nite Vacation Rental Listings - SQL Injection via detail.asp ID Parameter
CVE-2010-4633
digiSHOP 2.0.2 - SQL Injection via cart.php id Parameter
CVE-2010-4632
pilot_cart 7.3 - SQL Injection via Multiple Parameters
CVE-2010-4619
Mafya Oyun Scrpti - SQL Injection via profil.php id Parameter
CVE-2010-4615
Oto Galeri Sistemi 1.0 - SQL Injection via arac or marka Parameter
CVE-2010-4614
Ero Auktion 2010 - SQL Injection via item.php id Parameter
CVE-2010-4612
Hycus CMS 1.0.3 - SQL Injection via user_name, usr_email, useremail, or q Parameter
CVE-2010-4609
Html-edit CMS 3.1.8 - SQL Injection via nuser Parameter
CVE-2010-4517
JExtensions JE Auto (com_jeauto) 1.0 - SQL Injection via Char Parameter
CVE-2010-3922
Sixapart Movabletype - SQL Injection
CVE-2010-4505
Injader 2.4.4 - SQL Injection via Login Parameters
CVE-2010-4503
Aigaion 1.3.4 - SQL Injection via ID Parameter in export action
CVE-2010-4500
MRCGIGUY FreeTicket 1.0.0 - SQL Injection via contact.php Parameters
CVE-2010-4257
WordPress < 3.0.1 - Authenticated SQL Injection via Send Trackbacks Field
CVE-2010-4404
sh404SEF < 2.1.8.777 - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High