CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,930 vulnerabilities with CWE-89
CVE-2009-2021
Virtue Classifieds - SQL Injection via Search Category Parameter
CVE-2009-2019
Virtue News Manager - SQL Injection
CVE-2009-2018
Jared Eckersley MyCars - SQL Injection via authuserid Parameter
CVE-2009-2017
Virtue Book Store - SQL Injection via products.php cid Parameter
CVE-2009-2016
Virtue Shopping Mall - SQL Injection
CVE-2009-2014
Joomla ComSchool 1.4 - SQL Injection via classid Parameter
CVE-2009-2013
Frontis 3.9.01.24 - SQL Injection via source_class Parameter
CVE-2009-2010
Haudenschilt Family Connections CMS <1.9 - SQL Injection
CVE-2009-2008
Dokeos 1.8.5 - SQL Injection via uInfo or course Parameter
CVE-2009-2004
Dokeos 1.8.5 - SQL Injection via Student or Course Parameters
CVE-2009-1952
PropertyMax Pro FREE 0.3 - SQL Injection
CVE-2009-1950
WebEyes Guest Book 3 - SQL Injection
CVE-2009-1947
Unclassified NewsBoard (UNB) 1.6.4 - SQL Injection
CVE-2009-1945
WebCal 3.04 - SQL Injection via event_id Parameter
CVE-2009-1913
LuxBum 0.5.5 - SQL Injection via Username Parameter
CVE-2009-1910
RTWebalbum 1.0.462 - SQL Injection via AlbumId Parameter
CVE-2009-1909
Skip <1.0.2 & <1.1RC - SQL Injection
CVE-2009-1853
Kensei Board < 2.0.0b - SQL Injection via f and t Parameters
CVE-2009-1852
Graphiks MyForum 1.3 - SQL Injection via Username or Password Field
CVE-2009-1851
phpBugTracker < 1.0.4 - SQL Injection via Username Parameter
CVE-2009-1850
phpBugTracker 1.0.3 - SQL Injection via Password Parameter
CVE-2009-1848
JoomlaMe AgoraGroups 0.3.5.3 - SQL Injection via id Parameter
CVE-2009-1843
Flash Quiz Beta 2 - SQL Injection via Quiz or Order Number Parameter
CVE-2009-1842
PHP-Nuke 8.0 - SQL Injection via HTTP Referer Header
CVE-2009-1819
2daybiz Custom T-shirt Design Script - SQL Injection via product.php id Parameter
Details
Vulnerabilities
19,930
Exploit Likelihood
High