CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,915 vulnerabilities with CWE-89
CVE-2009-3967
Ed Charkow SuperCharged Linking - SQL Injection
CVE-2009-3965
New 5 Star Rating 1.0 - SQL Injection
CVE-2009-3964
com_ninjamonials 1.1.0 - SQL Injection via testimID Parameter
CVE-2009-3961
Super Serious Stats <1.1.2p1 - SQL Injection
CVE-2009-3913
Xerox Fiery Webtools - SQL Injection
CVE-2009-3835
JShop - SQL Injection via pid Parameter
CVE-2009-3834
Photoblog (com_photoblog) alpha 3 and alpha 3a - SQL Injection via Category Parameter
CVE-2009-3632
TYPO3 < 4.0.13, 4.1.x < 4.1.13, 4.2.x < 4.2.10, 4.3.x < 4.3beta2 - Authenticated SQL Injection
CVE-2009-3820
Flagbit Filebase 0.1.0 - SQL Injection
CVE-2009-3813
RunCMS 2M1 - Authenticated SQL Injection via Forum Parameter
CVE-2009-3806
dedecms 5.1 - SQL Injection via feedback_js.php arcurl Parameter
CVE-2009-3804
RunCMS 2M1 - Authenticated SQL Injection via Forum Post Parameters
CVE-2009-3801
OpenDocMan 1.2.5 - SQL Injection via Password Parameter
CVE-2009-3788
OpenDocMan 1.2.5 - SQL Injection via Username Parameter
CVE-2009-3778
Moodle Course List < 6.x-1.2 - SQL Injection
CVE-2009-3758
Citrix XenCenterWeb - SQL Injection via login.php Username Parameter
CVE-2009-3754
phpBMS 0.96 - SQL Injection via id/f/tid Parameters
CVE-2009-3752
Opial 1.0 - SQL Injection via Genres Parent Parameter
CVE-2009-3750
ToyLog 0.1 - SQL Injection via idm Parameter
CVE-2009-3718
Battle Blog 1.25 and 1.30 build 2 - SQL Injection via UserName Parameter
CVE-2009-3715
MCshoutbox 1.1 - SQL Injection via Username or Password Parameter
CVE-2009-3713
MorcegoCMS < 1.7.6 - SQL Injection via Fichero.php Query String
CVE-2009-3712
Ebay Clone 2009 - SQL Injection via user_id or item_id Parameter
CVE-2009-3697
phpMyAdmin 2.11.x-2.11.9.5 and 3.x-3.2.2.0 - SQL Injection via PDF Schema Generator
CVE-2009-2734
Achievo < 1.4.0 - SQL Injection via Userid Parameter
Details
Vulnerabilities
19,915
Exploit Likelihood
High