CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2009-4550
Kunena Forum <1.5.4 - SQL Injection
CVE-2009-4540
Mini CMS 1.0.1 - SQL Injection via Page ID Parameter
CVE-2009-4499
Zabbix Server <1.6.8 - SQL Injection
CVE-2009-4477
Xstate Real Estate 1.0 - SQL Injection
CVE-2009-4475
Joomlub com_joomlub - SQL Injection via aid Parameter
CVE-2009-4474
Mike de Boer zoom (com_zoom) 2.0 - SQL Injection
CVE-2009-4470
DVBBS 2.0 - SQL Injection via boardrule.php groupboardid Parameter
CVE-2009-4456
Green Desktiny <2.3.1 - SQL Injection
CVE-2009-4437
Active Auction House 3.6 - SQL Injection
CVE-2009-4436
eWebquiz 8 - SQL Injection via QuizID Parameter
CVE-2009-4432
CodeMight VideoCMS 3.1 - SQL Injection
CVE-2009-4430
VirtueMart 1.0 - SQL Injection via product_id Parameter
CVE-2009-4428
Joomla! com_joomportfolio 1.0.0 - SQL Injection
CVE-2009-4424
Pyrmont plugin 2 for WordPress - SQL Injection via id Parameter
CVE-2009-4423
weenCompany 4.0.0 - SQL Injection via moduleid Parameter
CVE-2009-4414
phpgwapi <0.9.16.014 - SQL Injection
CVE-2009-3582
SQL-Ledger 2.8.24 - Authenticated SQL Injection via Delete Subroutine Parameters
CVE-2009-4401
TYPO3 ste_parish_admin <0.1.3 - SQL Injection
CVE-2009-4399
TYPO3 hs_religiousartgallery <0.1.2 - SQL Injection
CVE-2009-4396
TYPO3 pd_resources <0.1.1 - SQL Injection
CVE-2009-4394
Random Prayer 2 <0.0.3 - SQL Injection
CVE-2009-4393
TYPO3 danp_documentdirs <1.10.7 - SQL Injection
CVE-2009-4392
TYPO3 xds_staff <0.0.3 - SQL Injection
CVE-2009-4390
Car (car) extension 0.1.1 - SQL Injection
CVE-2009-4386
Venalsur Booking Centre Booking System for Hotels Group - SQL Injection
Details
Vulnerabilities
19,915
Exploit Likelihood
High