CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,930 vulnerabilities with CWE-89
CVE-2009-1032
YABSoft Advanced Image Hosting Script 2.3 - SQL Injection via Gallery List gal Parameter
CVE-2009-1027
OpenCart 1.1.8 - SQL Injection via Order Parameter
CVE-2009-1026
Kim Websites 1.0 - SQL Injection via Username or Password Parameter
CVE-2009-1024
Beerwin PHPLinkAdmin 1.0 - SQL Injection via linkid Parameter
CVE-2009-1023
phpcomasy 0.9.1 - SQL Injection via entry_id Parameter
CVE-2009-0968
fMoblog plugin 2.1 - SQL Injection via id Parameter
CVE-2009-0965
Ganesha Digital Library 4.0 and 4.2 - SQL Injection via Node Parameter
CVE-2009-0963
PHPRunner < 4.2 - SQL Injection via SearchField Parameter
CVE-2009-0883
Blue Eye CMS <= 1.0.0 - SQL Injection via BlueEyeCMS_login Cookie Parameter
CVE-2009-0882
nForum 1.5 - SQL Injection via id or user Parameter
CVE-2009-0881
isiAJAX 1 - SQL Injection via id Parameter
CVE-2009-0863
S-Cms 1.1 - SQL Injection via id Parameter
CVE-2009-0825
TinX/cms < 3.5 - SQL Injection via RSS id Parameter
CVE-2009-0851
CelerBB 0.0.2 - SQL Injection via id Parameter
CVE-2009-0768
YapBB < 1.2 - SQL Injection via forumID Parameter
CVE-2009-0832
PHP-Fusion E-Cart 1.3 - SQL Injection
CVE-2009-0831
PHP-Fusion 1.0 - Members CV (job) module - SQL Injection
CVE-2009-0829
QuoteBook - SQL Injection via MyBox, selectFavorites, QuoteName, or QuoteText Parameters
CVE-2009-0810
xGuestbook 2.0 - SQL Injection via User Parameter
CVE-2009-0808
SimpleCMMS - SQL Injection
CVE-2009-0750
smNews - SQL Injection via Username Parameter
CVE-2009-0741
Craft Silicon Banking@Home <2.1 - SQL Injection
CVE-2009-0740
BlueBird Prelease - SQL Injection via Username or Passwd Parameter
CVE-2009-0739
MyNews 0.10 - SQL Injection via Username or Passwd Parameter
CVE-2009-0738
Auth Php 1.0 - SQL Injection via Username or Passwd Parameter
Details
Vulnerabilities
19,930
Exploit Likelihood
High