CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-2720
phpaaCms 0.3.1 UTF-8 - SQL Injection via list.php id Parameter
CVE-2010-2719
phpaaCms 0.3.1 UTF-8 - SQL Injection via show.php id Parameter
CVE-2010-2716
PsNews 1.3 - SQL Injection via id Parameter
CVE-2010-2714
TCW PHP Album 1.0 - SQL Injection via Album Parameter
CVE-2010-2699
Edge PHP Clickbank Affiliate Marketplace Script - SQL Injection
CVE-2010-2696
Sijio Community Software - SQL Injection
CVE-2010-2694
Joomla! com_redshop 1.0 - SQL Injection
CVE-2010-2691
2daybiz Custom T-Shirt Design Script - SQL Injection
CVE-2010-2690
JOOFORGE Gamesbox <1.0.2 - SQL Injection
CVE-2010-2689
Internet DM WebDM CMS - SQL Injection
CVE-2010-2688
Site2Nite Boat Classifieds - SQL Injection
CVE-2010-2687
Site2Nite Boat Classifieds - SQL Injection
CVE-2010-2686
TopManage OLK module 1.91.30 - SQL Injection
CVE-2010-2684
Customer Paradigm PageDirector CMS - SQL Injection
CVE-2010-2683
Customer Paradigm PageDirector CMS - SQL Injection
CVE-2010-2679
Joomla! com_weblinks - SQL Injection via id Parameter
CVE-2010-2678
com_xmap - SQL Injection via Itemid Parameter
CVE-2010-2674
TSOKA:CMS 1.1, 1.9, 2.0 - SQL Injection via id Parameter
CVE-2010-2673
Devana < 1.6.6 - SQL Injection via Profile View ID Parameter
CVE-2010-2672
eZ Publish 3.7.0-4.2.0 - SQL Injection via Search Parameters
CVE-2010-2670
BrotherScripts Recipe Website - SQL Injection
CVE-2010-1669
Mahara 1.1.x < 1.1.9 and 1.2.x < 1.2.5 - SQL Injection
CVE-2010-1327
TornadoStore <1.4.3 - SQL Injection
CVE-2010-2624
iScripts EasySnaps 2.0 - SQL Injection via Comment Parameter
CVE-2010-2623
Internet DM Specialist Bed and Breakfast - SQL Injection via pp_id Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High