CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2010-0692
IP-Tech JQuarks (com_jquarks) 0.2.3 - SQL Injection
CVE-2010-0691
JTL-Shop 2 - SQL Injection via Druckansicht s Parameter
CVE-2010-0690
CommodityRentals Video Games Rentals - SQL Injection
CVE-2010-0677
Katalog Stron Hurricane 1.3.5 - SQL Injection via Index.php Get Parameter
CVE-2010-0673
Copperleaf Photolog 0.16 - SQL Injection via postid Parameter
CVE-2010-0672
WSN Guest 1.02 - SQL Injection via Orderlinks Parameter
CVE-2010-0671
KR MEDIA Pogodny CMS - SQL Injection via id Parameter in niusy Action
CVE-2010-0635
JEvents Search Plugin 1.5-1.5.3 - SQL Injection via plgSearchEventsearch::onSearch Method
CVE-2010-0632
Parkview Consultants SimpleFAQ - SQL Injection via catid Parameter
CVE-2010-0631
eicra_car_rental-script - SQL Injection via Users and Passwords Parameters
CVE-2010-0630
Evernew Free Joke Script 1.2 - SQL Injection via viewjokes.php id Parameter
CVE-2010-0614
evalSMSI 2.1.03 - SQL Injection via ajax.php query parameter
CVE-2010-0611
baal_systems < 3.8 - SQL Injection via adminlogin.php Username and Password Parameters
CVE-2010-0610
com_photoblog - SQL Injection via Blog Parameter
CVE-2010-0609
NovaBoard 1.1.2 - SQL Injection via nova_name Cookie Parameter
CVE-2010-0608
NovaBoard 1.1.2 - SQL Injection via forums[] Parameter
CVE-2010-0605
osTicket < 1.6 - Authenticated SQL Injection via scp/ajax.php Input Parameter
CVE-2010-0438
OTRS 2.1.x-2.1.9, 2.2.x-2.2.9, 2.3.x-2.3.5, 2.4.x-2.4.7 - Authenticated SQL Injection
CVE-2010-0471
Enanocms < 1.0.6 - SQL Injection
CVE-2010-0469
Files2Links F2L 3000 Appliance 4.0.0 - SQL Injection via Login Page Parameters
CVE-2010-0461
Joomla com_casino 1.0 - SQL Injection via id Parameter
CVE-2010-0459
com_mochigames 0.51 - SQL Injection via id Parameter
CVE-2010-0458
NetArt Media Blog System 1.5 - SQL Injection via cat or note Parameter
CVE-2010-0457
magic-portal 2.1 - SQL Injection via home.php id Parameter
CVE-2010-0456
indianpulse Game Server (com_gameserver) 1.2 - SQL Injection via grp Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High