CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-2340
Arab Portal 2.2 - SQL Injection via Members.php by Parameter
CVE-2010-2339
Subdreamer CMS 3.x.x - SQL Injection via categoryids[] Parameter
CVE-2010-2338
VU Web Visitor Analyst - SQL Injection via redir.asp Username or Password Parameter
CVE-2010-2335
Yamamah Photo Gallery 1.00 - SQL Injection via News Parameter
CVE-2010-2319
IDevSpot TextAds 2.08 - SQL Injection via Page Parameter
CVE-2010-2317
WmsCms < 2.0 - SQL Injection via Multiple Parameters
CVE-2010-2312
HauntmAx Haunted House Directory Listing CMS - SQL Injection via State Parameter
CVE-2010-1931
CubeCart 4.3.4-4.3.9 - SQL Injection via shipKey Parameter
CVE-2010-2257
Pay Per Minute Video Chat Script 2.0-2.1 - SQL Injection via index_ie.php page Parameter
CVE-2010-2255
Tamlyncreative Com Bfsurvey Profree < 1.3.0 - SQL Injection
CVE-2010-2254
Shape5 Bridge of Hope Template - SQL Injection via id Parameter
CVE-2010-1904
EMC RSA Key Manager C Client 1.5.x - SQL Injection via Encrypted Key Metadata
CVE-2010-2148
com_mycar 1.0 - SQL Injection via Pagina Parameter
CVE-2010-2142
Cyberhost - SQL Injection via default.asp id Parameter
CVE-2010-2141
nitro_web_gallery - SQL Injection via PictureId Parameter
CVE-2010-2140
Multishop CMS - SQL Injection via itemid Parameter
CVE-2010-2139
Multishop CMS - SQL Injection via pages.php id Parameter
CVE-2010-2135
HazelPress Lite <= 0.0.4 - SQL Injection via Username or Password Field
CVE-2010-2134
Project Man 1.0 - SQL Injection via Username or Password Parameter
CVE-2010-2133
My Little Forum - SQL Injection via Contact.php ID Parameter
CVE-2010-2131
Calendar Base (cal) < 1.3.2 - SQL Injection via iCalendar Data
CVE-2010-2124
ConPresso 4.0.7 - SQL Injection via Firma.php ID Parameter
CVE-2010-2095
CMSQlite < 1.2 - SQL Injection via c Parameter
CVE-2010-2092
Cacti < 0.8.7e - SQL Injection via rra_id Parameter
CVE-2010-2051
Debliteck DBCart - SQL Injection via article.php id Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High