CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,930 vulnerabilities with CWE-89
CVE-2009-2164
Kjtechforce Mailman Beta1 - SQL Injection
CVE-2009-2157
TorrentTrader Classic 1.09 - SQL Injection
CVE-2009-2154
Impleo Music Collection 2.0 - SQL Injection
CVE-2009-2152
AdaptWeb 0.9.2 - SQL Injection via CodigoDisciplina Parameter
CVE-2009-2148
Campus Virtual-LMS - SQL Injection via News ID Parameter
CVE-2009-2147
phpWebThings <1.5.2 - SQL Injection
CVE-2009-2144
FireStats <1.6.2- stable - SQL Injection
CVE-2009-2142
Zip Store Chat 4.0-5.0 - SQL Injection
CVE-2009-2128
elvinbts < 1.2.1 - SQL Injection via Title Field
CVE-2009-2123
elvinbts 1.2.0 - SQL Injection via Username or Password Parameter
CVE-2009-2122
Paolo Palmonari Photoracer <1.0 - SQL Injection
CVE-2009-2120
TekBase All-in-One 3.1 - SQL Injection
CVE-2009-2113
FretsWeb 1.2 - SQL Injection via Name or Hash Parameter
CVE-2009-2106
TYPO3 civserv <4.3.2 - SQL Injection
CVE-2009-2105
TYPO3 t3references <0.1.1 - SQL Injection
CVE-2009-2103
Frontend MP3 Player <0.2.3 - SQL Injection
CVE-2009-2102
Joomla com_jumi 2.0.3 - SQL Injection
CVE-2009-2099
ijoomla com_rssfeeder - SQL Injection via cat Parameter
CVE-2009-2098
phPortal 1.0 - SQL Injection via Topicler id Parameter
CVE-2009-2097
Zoki Soft Zoki Catalog - SQL Injection
CVE-2009-2096
phpCollegeExchange 0.1.5c - SQL Injection
CVE-2009-2082
Creative Web Solutions Multi-Level CMS 1.21 - SQL Injection
CVE-2009-2036
Open Biller 0.1 - SQL Injection via Username Parameter
CVE-2009-2034
Yogurt 0.3 - Authenticated SQL Injection via Original Parameter
CVE-2009-2023
Shop-Script Pro 2.12 - SQL Injection
Details
Vulnerabilities
19,930
Exploit Likelihood
High