CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-2047
JE CMS 1.0.0 and 1.1 - SQL Injection via CategoryID Parameter
CVE-2010-2044
com_konsultasi 1.0.0 - SQL Injection via sid Parameter
CVE-2010-2042
ECShop 2.7.2 - SQL Injection via Search Encode Parameter
CVE-2010-2019
Lokomedia CMS 1.4.1 - SQL Injection via File Parameter
CVE-2010-2016
Iceberg CMS - SQL Injection via p_id Parameter
CVE-2010-2015
LiSK CMS 4.4 - SQL Injection via id Parameter
CVE-2010-2012
MigasCMS 1.1 - SQL Injection via Categorie Parameter
CVE-2010-1994
TomatoCMS < 2.0.5 - SQL Injection via News Search q Parameter
CVE-2010-0404
phpGroupWare < 0.9.16.016 - SQL Injection
CVE-2010-1950
com_jnewspaper 1.0 - SQL Injection via date_info Parameter
CVE-2010-1949
com_jnewspaper 1.0 - SQL Injection via cid Parameter
CVE-2010-1925
tekno.Portal 0.1b - SQL Injection via makale.php id Parameter
CVE-2010-1924
Live Shopping Multi Portal System - SQL Injection via Artikel Parameter
CVE-2010-1923
Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System - SQL Injection via id Parameter
CVE-2010-1918
efront < 3.6.2 - SQL Injection via chatrooms_ID Parameter
CVE-2010-1877
JTM Reseller (com_jtm) 1.9 Beta - SQL Injection via Author Parameter
CVE-2010-1876
AJ Shopping Cart 1.0 - SQL Injection via maincatid Parameter
CVE-2010-1874
Real Estate Property (com_properties) 3.1.22-03 - SQL Injection via aid Parameter
CVE-2010-1873
com_jvehicles 1.0, 2.0, and 2.1111 - SQL Injection via aid Parameter
CVE-2010-1867
Campsite < 3.3.5 - SQL Injection via ArticleAttachment article_id Parameter
CVE-2010-1865
ClanSphere < 2009.0.3 - SQL Injection via Captcha IP Address or MySQL Driver s_email Parameter
CVE-2010-1863
ClanTiger <= 1.1.3 - SQL Injection via Shoutbox s_email Parameter
CVE-2010-1859
DeluxeBB < 1.3 - SQL Injection via membercookie Cookie
CVE-2010-1857
RepairShop2 1.9.023 Trial - SQL Injection via prod Parameter
CVE-2010-1855
Pay Per Watch & Bid Auktions System - SQL Injection via id_auk Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High