CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2009-4719
Discloser 0.0.4 rc2 - SQL Injection
CVE-2009-4718
Gonafish WebStatCaffe - SQL Injection
CVE-2009-4712
Tukanas Classifieds <1.0 - SQL Injection
CVE-2009-4711
CoolURI < 1.0.16 - SQL Injection
CVE-2009-4710
TYPO3 cwt_resetbepassword <1.20 - SQL Injection
CVE-2009-4709
TYPO3 datamints_newsticker <0.7.2 - SQL Injection
CVE-2009-4708
TYPO3 Gobernalia <0.1.0 - SQL Injection
CVE-2009-4703
Webesse Image Gallery <1.0.4 - SQL Injection
CVE-2009-4702
TYPO3 pm_tour <0.0.13 - SQL Injection
CVE-2009-4701
Myth Download <0.1.0 - SQL Injection
CVE-2009-4698
XOOPS Celepar Qas Module - SQL Injection via codigo or cod_categoria Parameter
CVE-2009-4696
RadNICS Gold 5 - SQL Injection via fid Parameter
CVE-2009-4695
RadScripts RadLance Gold 7.5 - SQL Injection
CVE-2009-4691
Classified Linktrader Script - SQL Injection
CVE-2009-4689
PHP Shopping Cart Selling Website Script - SQL Injection
CVE-2009-4687
Silentum Guestbook 2.0.2 - SQL Injection
CVE-2009-4680
phpDirectorySource 1.x - SQL Injection
CVE-2009-4673
Mole Group Adult Portal Script - SQL Injection
CVE-2009-4669
RoomPHPlanning 1.6 - SQL Injection via Login Parameter or Old Password Field
CVE-2009-4667
WebMember 1.0 - Authenticated SQL Injection via formID Parameter
CVE-2009-4650
Webee Comments (com_webeecomment) 1.1.1, 1.2, 2.0 - SQL Injection
CVE-2009-4015
Lintian 1.23.x-1.23.28, 1.24.x-1.24.2.1, 2.x < 2.3.2 - Remote Command Execution via Filename Shell Metacharacters
CVE-2009-4628
Joomla! com_tpdugg 1.1 - SQL Injection
CVE-2009-4625
BF Survey Pro Free <1.2.6 - SQL Injection
CVE-2009-4624
Nicecoder iDesk - SQL Injection via download.php cat_id Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High