CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,930 vulnerabilities with CWE-89
CVE-2009-2554
Joomla! Jobline <1.3.1 - SQL Injection
CVE-2009-2553
Super Simple Blog Script 2.5.4 - SQL Injection
CVE-2009-2545
Advanced Electron Forum 1.x - SQL Injection
CVE-2009-2451
MIM:InfiniX <1.2.003 - SQL Injection
CVE-2009-2439
Web Development House Alibaba Clone - SQL Injection
CVE-2009-2436
MyPHPDating 1.0 - SQL Injection via Page ID Parameter
CVE-2009-2428
Tausch Ticket Script 3 - SQL Injection
CVE-2009-2427
Jobbr 2.2.7 - SQL Injection via emp_id Parameter
CVE-2009-2423
Ebay Clone 2009 - SQL Injection via cate_id Parameter
CVE-2009-2402
PHPEcho CMS <2.0-rc3 - SQL Injection
CVE-2009-2400
com_php - SQL Injection via id Parameter
CVE-2009-2395
com_k2 < 1.0.1 - SQL Injection via Category Parameter
CVE-2009-2394
SMSPages 1.0 - SQL Injection via CatID Parameter
CVE-2009-2392
Virtuenetz Virtue Online Test Generator - SQL Injection
CVE-2009-2390
com_bookflip 2.1 - SQL Injection via book_id Parameter
CVE-2009-2389
USOLVED NEWSolved 1.1.6 - SQL Injection
CVE-2009-2388
Opial 1.0 - SQL Injection via txtPassword Parameter
CVE-2009-2385
Simple Machines Forum 1.0.2 - SQL Injection
CVE-2009-2383
WordPress Related Sites 2.1 - SQL Injection
CVE-2009-2366
DataCheck Solutions ForumPal FE 1.1 & 1.5 - SQL Injection
CVE-2009-2365
DataCheck Solutions GalleryPal FE 1.5 - SQL Injection
CVE-2009-2361
osTicket < 1.6 - SQL Injection via Staff Username Parameter
CVE-2009-2359
TekRADIUS 3.0 - SQL Injection via GUI Client or Command-Line Client
CVE-2009-2354
NullLogic Groupware 1.2.7 - SQL Injection
CVE-2009-2345
ClanSphere <2009.0.1 - SQL Injection
Details
Vulnerabilities
19,930
Exploit Likelihood
High