CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-1093
1024 CMS 2.1.1 - SQL Injection via RSS.php id Parameter
CVE-2010-1092
ScriptsFeed Business Directory Software - SQL Injection
CVE-2010-1090
phpmysite - SQL Injection via Index.php Action Parameter
CVE-2010-1089
PHP Trouble Ticket 2.2 - SQL Injection
CVE-2010-1078
XlentProjects SphereCMS 1.1 - SQL Injection
CVE-2010-1075
Entry Level CMS - SQL Injection via index.php subj Parameter
CVE-2010-1073
com_jembed - SQL Injection via catid Parameter
CVE-2010-1071
phpmdj 1.0.3 - SQL Injection via profil.php id Parameter
CVE-2010-1070
ImagoScripts Deviant Art Clone - SQL Injection
CVE-2010-1069
ProArcadeScript - SQL Injection via Games ID Parameter
CVE-2010-1054
ParsCMS - SQL Injection via RP Parameter
CVE-2010-1053
Zen Time Tracking <2.2 - SQL Injection
CVE-2010-1051
AudiStat 1.3 - SQL Injection via Year or Month Parameter
CVE-2010-1050
AudiStat 1.3 - SQL Injection via mday Parameter
CVE-2010-1049
Uiga Business Portal - SQL Injection
CVE-2010-1047
MASA2EL Music City <1.1 - SQL Injection
CVE-2010-1046
rostermain < 1.1 - SQL Injection via Userid or Password Parameter
CVE-2010-1045
Joomla! com_productbook 1.0.4 - SQL Injection
CVE-2010-1044
ManageEngine OpUtils 5.0 - SQL Injection
CVE-2010-1027
Meet Travelmates <0.1.1 - SQL Injection
CVE-2010-1026
CleanDB - DBAL <2.1.0 - SQL Injection
CVE-2010-1024
TGM-Newsletter <0.0.2 - SQL Injection
CVE-2010-1019
Simple Gallery <0.0.9 - SQL Injection
CVE-2010-1018
TYPO3 sk_bookreview <0.0.12 - SQL Injection
CVE-2010-1017
TYPO3 sav_filter_months <1.0.5 - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High