CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-1016
TYPO3 sav_filter_selectors <1.0.5 - SQL Injection
CVE-2010-1015
TYPO3 sav_filter_abc <1.0.9 - SQL Injection
CVE-2010-1013
TYPO3 pd_diocesedatabase <0.7.13 - SQL Injection
CVE-2010-1012
TYPO3 nf_cleandb <1.0.7 - SQL Injection
CVE-2010-1010
MK Wastebasket <2.1.0 - SQL Injection
CVE-2010-1009
TYPO3 Educator 0.1.5 - SQL Injection
CVE-2010-1006
TYPO3 Brainstorming <0.1.8 - SQL Injection
CVE-2010-1004
Yet another TYPO3 search engine <0.3.2 - SQL Injection
CVE-2010-0981
TPJobs for Joomla! - SQL Injection via id_c[] Parameter
CVE-2010-0980
Left 4 Dead (L4D) Stats 1.1 - SQL Injection
CVE-2010-0974
PHPCityPortal - SQL Injection via id Parameter
CVE-2010-0973
phppool media Domain Verkaus and Auktions Portal - SQL Injection
CVE-2010-0970
PhpMyLogon 2 - SQL Injection via Username Parameter
CVE-2010-0968
Geekhelps ADMP 1.01 - SQL Injection
CVE-2010-0964
Eros Webkatalog - SQL Injection via start.php id Parameter
CVE-2010-0122
Employee Timeclock Software 0.99 - SQL Injection via Username or Password Parameter
CVE-2010-0956
OpenCart 1.3.2 - SQL Injection via Page Parameter
CVE-2010-0955
Bild Flirt Community 2.0 - SQL Injection
CVE-2010-0954
Pre Projects Pre E-Learning Portal - SQL Injection
CVE-2010-0952
OneCMS 2.5 - SQL Injection via User Parameter in Elite Action
CVE-2010-0951
dev4u CMS - SQL Injection via go_target.php kontent_id Parameter
CVE-2010-0950
Natychmiast CMS - SQL Injection via id_str Parameter
CVE-2010-0948
Bigforum 4.5 - SQL Injection via profil.php id Parameter
CVE-2010-0946
com_ksadvertiser - SQL Injection via pid Parameter
CVE-2010-0945
Joomla! com_hotbrackets - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High