CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-0803
Joomla! com_jvideodirect 1.1 RC3b - SQL Injection
CVE-2010-0802
(nv2) Awards 1.1.0 - SQL Injection via id Parameter
CVE-2010-0800
Ossolution Team Documents Seller <2.5.1 - SQL Injection
CVE-2010-0798
T3BLOG < 0.6.2 - SQL Injection
CVE-2010-0796
JE Quiz (com_jequizmanagement) 1.b01 - SQL Injection via eid Parameter
CVE-2010-0795
JE Event Calendars (com_jeeventcalendar) 1.0 - SQL Injection
CVE-2010-0764
KuwaitPHP eSmile - SQL Injection via cid Parameter
CVE-2010-0763
CommodityRentals Vacation Rental Software - SQL Injection
CVE-2010-0762
CommodityRentals CD Rental Software - SQL Injection
CVE-2010-0761
CommodityRentals Books/eBooks Rentals Script - SQL Injection
CVE-2010-0758
Softbiz Jobs and Recruitment Script - SQL Injection via news_desc.php id Parameter
CVE-2010-0753
Joomla! com_sqlreport 1.1 - SQL Injection
CVE-2010-0724
Arab Cart 1.0.2.0 - SQL Injection via showimg.php id Parameter
CVE-2010-0723
Ero Auktion 2.0 and 2010 - SQL Injection via News.php ID Parameter
CVE-2010-0722
php_auktion_pro - SQL Injection via news.php id Parameter
CVE-2010-0721
Auktionshaus Gelb 3.0 - SQL Injection
CVE-2010-0720
Erotik Auktionshaus - SQL Injection
CVE-2010-0712
Zenoss < 2.5 - Authenticated SQL Injection via Events API Parameters
CVE-2010-0710
ASPCode CMS <2.0.0 Build 103 - SQL Injection
CVE-2010-0702
Fonality Trixbox 2.2.4 - SQL Injection
CVE-2010-0701
Newgen Software OmniDocs - SQL Injection
CVE-2010-0698
Dynamicsoft WSC CMS 2.2 - SQL Injection
CVE-2010-0147
Cisco Security Agent Management Center 5.1-5.2, 6.0 - Authenticated SQL Injection
CVE-2010-0694
PerchaGallery <1.5b - SQL Injection
CVE-2010-0693
CommodityRentals Trade Manager Script - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High