CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2009-4199
Mambo Resident 1.0f - SQL Injection
CVE-2009-4198
MyMiniBill - Authenticated SQL Injection via orderid Parameter
CVE-2009-4166
TYPO3 mchtrips 2.0.0 - SQL Injection
CVE-2009-4165
TYPO3 simple Glossar <1.0.3 - SQL Injection
CVE-2009-4163
TYPO3 tw_productfinder <0.0.2 - SQL Injection
CVE-2009-4158
Calendar Base (cal) < 1.2.1 - SQL Injection
CVE-2009-4155
Eshopbuilde CMS - SQL Injection via Multiple Parameters
CVE-2009-4104
LyftenBloggie 1.0.4 - SQL Injection
CVE-2009-4099
Google Calendar GCalendar <2.1.4 - SQL Injection
CVE-2009-4084
e107 < 0.7.16 - SQL Injection via Search Feature
CVE-2009-4070
GForge 4.5.14 4.7.3 - SQL Injection
CVE-2009-4060
CubeCart < 4.3.7 - SQL Injection via productId Parameter
CVE-2009-4059
JoomClip - SQL Injection via Cat Parameter
CVE-2009-4058
Telebid Auction Script - SQL Injection
CVE-2009-4057
Joomla! com_if_nexus 1.1 - SQL Injection
CVE-2009-4046
FrontAccounting 2.2.x - SQL Injection
CVE-2009-4045
FrontAccounting <2.1.7 - SQL Injection
CVE-2009-4037
FrontAccounting <2.1.7 & 2.2.x - SQL Injection
CVE-2009-3975
Moa Gallery 1.1.0 and 1.2.0 - SQL Injection via gallery_id Parameter
CVE-2009-3974
Invision Power Board <3.0.2 - SQL Injection
CVE-2009-3973
Turnkey Arcade Script - SQL Injection
CVE-2009-3972
Joomla! com_siirler 1.2 RC - SQL Injection
CVE-2009-3971
jtips com_jtips - SQL Injection via Season Parameter
CVE-2009-3970
PHP Dir Submit - Authenticated SQL Injection via aid Parameter
CVE-2009-3968
ITechBids 8.0 - SQL Injection via User ID, Category ID, News ID, or Product ID Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High