CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-0112
Symantec IM Manager < 8.4.16 - SQL Injection via Administrative Interface
CVE-2010-3076
Simple Management for BIND <0.4.8 - SQL Injection
CVE-2010-3608
wpQuiz 2.7 - SQL Injection via id or password Parameter
CVE-2010-3604
powermail < 1.5.2 - SQL Injection
CVE-2010-3601
ibPhotohost 1.1.2 - SQL Injection via img Parameter
CVE-2010-3485
LightNEasy 3.2.1 - SQL Injection via Userhandle Cookie
CVE-2010-3484
LightNEasy 3.2.1 - SQL Injection via Handle Parameter
CVE-2010-3482
Primitive CMS 1.0.9 - SQL Injection
CVE-2010-3481
ApPHP PHP MicroCMS 1.0.1 - SQL Injection
CVE-2010-3479
BoutikOne 1.0 - SQL Injection via Page Parameter
CVE-2010-3467
E-Xoopport Samsara <3.1 - SQL Injection
CVE-2010-3461
eNdonesia 8.4 - SQL Injection via Publisher Module artid Parameter
CVE-2010-3458
Symphony CMS <2.1.1 - SQL Injection
CVE-2010-3428
Intermesh Group-Office 3.5.9 - SQL Injection
CVE-2010-3423
Drupal 6.x <6.x-1.6 - SQL Injection
CVE-2010-3422
Joomla! com_jgen 0.9.33 - SQL Injection
CVE-2010-3404
eshtery CMS - SQL Injection via Criteria Field or Admin Login Username
CVE-2010-3212
Seagull <= 0.6.7 - SQL Injection via frmQuestion Parameter
CVE-2010-3211
JE FAQ Pro 1.5.0 - SQL Injection
CVE-2010-3207
galeriashqip 1.0 - SQL Injection via album_id Parameter
CVE-2010-3188
BugTracker.NET <3.4.3 - SQL Injection
CVE-2010-2826
Cisco WCS <6.0.196.0 - SQL Injection
CVE-2010-3029
phpkick 0.8 - SQL Injection via Gameday Parameter
CVE-2010-3027
Tycoon Baseball Script 1.0.9 - SQL Injection
CVE-2010-3013
Pligg CMS < 1.1.1 - SQL Injection via Role Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High