CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,930 vulnerabilities with CWE-89
CVE-2009-0730
GigCalendar (com_gigcal) 1.0 - SQL Injection via gigcal_venues_id or gigcal_bands_id Parameter
CVE-2009-0728
MAXdev MDPro/Postnuke - SQL Injection
CVE-2009-0727
taifajobs < 1.0 - SQL Injection via jobid Parameter
CVE-2009-0726
GigCalendar (com_gigcal) 1.0 - SQL Injection
CVE-2009-0709
PHPFootball 1.6 - SQL Injection via User Parameter
CVE-2009-0707
PowerClan 1.14a - SQL Injection via Login Email Parameter
CVE-2009-0706
Joomla! & Mambo 1.3.5 - SQL Injection
CVE-2009-0705
PowerScripts PowerNews <2.5.4 - SQL Injection
CVE-2009-0704
WSN Guest 1.23 - SQL Injection via Search Parameter
CVE-2009-0703
ASPThai.Net Webboard 6.0 - SQL Injection
CVE-2009-0702
Phoca com_phocadocumentation - SQL Injection via id Parameter
CVE-2009-0672
RavenNuke 2.30 - Authenticated SQL Injection via Resend_Email Module user_prefix Parameter
CVE-2009-0646
4site CMS < 2.6 - SQL Injection via Multiple Parameters
CVE-2009-0604
php_director < 0.21 - SQL Injection via Searching Parameter
CVE-2009-0598
PhpMesFilms 1.0 and 1.8 - SQL Injection via id Parameter
CVE-2009-0597
w3b_cms < 3.3.0 - SQL Injection via Username Parameter
CVE-2009-0593
plx Auto Reminder 3.7 - SQL Injection
CVE-2009-0574
Easy CafeEngine - SQL Injection via catid Parameter
CVE-2009-0543
ProFTPD Server <1.3.1 - Auth Bypass
CVE-2009-0542
ProFTPD Server <1.3.2rc2 - SQL Injection
CVE-2009-0534
FlexCMS - SQL Injection via catId Parameter
CVE-2009-0531
A Better Member-Based ASP Photo Gallery <1.2 - SQL Injection
CVE-2009-0528
Rhadrix If-CMS <2.07 - SQL Injection
CVE-2009-0516
BusinessSpace < 1.2 - SQL Injection via Classified Page id Parameter
CVE-2009-0462
ClickTech ClickCart 6.0 - SQL Injection
Details
Vulnerabilities
19,930
Exploit Likelihood
High