CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,929 vulnerabilities with CWE-89
CVE-2009-2921
MOC Designs PHP News 1.1 - SQL Injection via User or Password Field
CVE-2009-2915
2fly Gift Delivery System 6.0 - SQL Injection via gameid Parameter
CVE-2009-2895
Ultimate Regnow Affiliate 3.0 - SQL Injection via RSS cat Parameter
CVE-2009-2894
Ebay Clone 2009 - SQL Injection via id or cid Parameter
CVE-2009-2892
Scripteen Free Image Hosting Script 2.3 - SQL Injection via cookid or cookgid Cookie
CVE-2009-2891
PHP Scripts Now Riddles - SQL Injection via list.php catid Parameter
CVE-2009-2888
PHP Scripts Now Hangman - SQL Injection via index.php n Parameter
CVE-2009-2886
PHP Scripts Now President Bios - SQL Injection via Rank Parameter
CVE-2009-2885
PHP Scripts Now World's Tallest Buildings - SQL Injection via bios.php rank Parameter
CVE-2009-2883
SaphpLesson 4.0 - SQL Injection via cp_username Parameter
CVE-2009-2881
Basilic 1.5.13 - SQL Injection via idAuthor Parameter
CVE-2009-2790
SoftBiz Dating Script - SQL Injection
CVE-2009-2789
Permis com_groups 1.0 - SQL Injection via id Parameter
CVE-2009-2788
Mobilelib GOLD 3 - SQL Injection via adminName Parameter
CVE-2009-2786
PunBB Reputation <2.2.4 - SQL Injection
CVE-2009-2782
JFusion com_jfusion - SQL Injection via Itemid Parameter
CVE-2009-2781
Arab Portal 2.x - Authenticated SQL Injection via forum.php qc Parameter
CVE-2009-2779
ajsquare aj_matrix_dna - SQL Injection via id Parameter in productdetail Action
CVE-2009-2777
GarageSales Script - SQL Injection via visitor/view.php key Parameter
CVE-2009-2776
Smart ASP Survey - SQL Injection via showresult.asp catid Parameter
CVE-2009-2775
PHPArcadeScript 4.0 - SQL Injection
CVE-2009-2774
PHP Paid 4 Mail Script - SQL Injection
CVE-2009-2093
IBM WebSphere Partner Gateway 6.0-6.2 - Authenticated SQL Injection
CVE-2009-2735
sun-jester OpenNews 1.0 - SQL Injection via Username Parameter
CVE-2009-2579
CS-Cart < 2.0.6 - Authenticated SQL Injection via Reward Points sort_order Parameter
Details
Vulnerabilities
19,929
Exploit Likelihood
High