CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2009-0431
LinksPro Standard Edition - SQL Injection
CVE-2009-0429
Active Bids - SQL Injection via search.asp search Parameter
CVE-2009-0428
DMXReady Secure Document Library <1.1 - SQL Injection
CVE-2009-0427
DMXReady Member Directory Manager <1.1 - SQL Injection
CVE-2009-0426
DMXReady Classified Listings Manager <1.1 - SQL Injection
CVE-2009-0425
Blue Eye CMS <1.0.0 - SQL Injection
CVE-2009-0421
Joomla com_eventing 1.6.x - SQL Injection via catid Parameter
CVE-2009-0420
RD-Autos 1.5.5 Stable - SQL Injection via id Parameter
CVE-2009-0409
Max.Blog <= 1.0.6 - SQL Injection via Username Parameter
CVE-2009-0407
PHP-CMS Project 1 - SQL Injection via Username Parameter
CVE-2009-0406
Community CMS < 0.4 - SQL Injection via id Parameter
CVE-2009-0405
smartsitecms 1.0 - SQL Injection via articles.php var Parameter
CVE-2009-0403
Chipmunk Blogger Script - SQL Injection
CVE-2009-0402
Domain Technologie Control <0.29.16 - SQL Injection
CVE-2009-0401
e-php_cms - SQL Injection via browsecats.php cid Parameter
CVE-2009-0400
SocialEngine 3.06 - SQL Injection via Blog Category ID Parameter
CVE-2009-0395
NetArt Media Car Portal 1.0 - SQL Injection
CVE-2009-0394
PLEs CMS 1.0 beta 4.2 - SQL Injection
CVE-2009-0384
OwnRS CMS 1.2 - SQL Injection via autor.php id Parameter
CVE-2009-0381
Joomla! com_prod 5.0 - SQL Injection
CVE-2009-0380
Sigsiu Online Business Index 2 <RC 2.8.2 - SQL Injection
CVE-2009-0379
Joomla! com_pcchess - SQL Injection
CVE-2009-0377
Joomla! beamospetition <1.0.12 - SQL Injection
CVE-2009-0373
ElearningForce Flash Magazine Deluxe - SQL Injection via mag_id Parameter
CVE-2009-0339
DMXReady Blog Manager - SQL Injection
Details
Vulnerabilities
19,944
Exploit Likelihood
High