CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-1744
B2B Gold Script - SQL Injection via id Parameter
CVE-2010-1743
Scratcher - SQL Injection via projects.php id Parameter
CVE-2010-1741
Billwerx RC 5.2.2 PL2 - SQL Injection via Primary Number Parameter
CVE-2010-1740
GuppY 4.5.18 - SQL Injection via Newsletter lng Parameter
CVE-2010-1739
Joomla! Newsfeeds Component - SQL Injection via feedid Parameter
CVE-2010-1727
JobPost 1.0 - SQL Injection via iType Parameter
CVE-2010-1726
EC21 Clone 3.0 - SQL Injection via offers_buy.php id Parameter
CVE-2010-1725
Alibaba Clone Platinum - SQL Injection via offers_buy.php id Parameter
CVE-2010-1733
OCS Inventory NG < 1.02.3 - SQL Injection via Search Form Fields
CVE-2010-1583
Tirzen Framework <1.5 - SQL Injection
CVE-2010-1721
com_iproperty 1.5.3 - SQL Injection via id Parameter
CVE-2010-1720
com_qpersonel < 1.0.2 - SQL Injection via katid Parameter
CVE-2010-1716
com_agenda 1.0.1 - SQL Injection via id Parameter
CVE-2010-1713
PostNuke 0.764 - SQL Injection via News Article modload sid Parameter
CVE-2010-1708
Free Realty - SQL Injection via Agent Login or Password Parameter
CVE-2010-1706
2daybiz Auction Script - SQL Injection via Login Username Parameter
CVE-2010-1705
Modelbook - SQL Injection via casting_view.php adnum Parameter
CVE-2010-1704
2daybiz Polls Script - SQL Injection via Login Parameters
CVE-2010-1702
WHMCS 4.2 - SQL Injection via submitticket.php deptid Parameter
CVE-2010-1701
PHP Video Battle Script - SQL Injection via browse.html cat Parameter
CVE-2010-1431
Cacti < 0.8.7e - SQL Injection via Export Item ID Parameter
CVE-2010-1661
PHP-Quick-Arcade 3.0.21 - SQL Injection via phpqa_user_c or id Parameter
CVE-2010-1660
CLScript Classifieds Script - SQL Injection via help-details.php hpId Parameter
CVE-2010-1656
Airiny ABC 1.1.7 - SQL Injection via Sectionid Parameter
CVE-2010-1654
Infocus Real Estate Enterprise Edition - SQL Injection via Username or Password Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High