CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2009-0337
Katy Whitton BlogIt! - SQL Injection
CVE-2009-0334
Katy Whitton BlogIt! - SQL Injection
CVE-2009-0333
Joomla com_waticketsystem - SQL Injection via catid Parameter
CVE-2009-0332
AV Book Library <1.1 - SQL Injection
CVE-2009-0329
PcCookBook - Joomla! - SQL Injection
CVE-2009-0327
Free Bible Search PHP Script 1.0 - SQL Injection
CVE-2009-0326
Dark Age CMS 0.2c beta - SQL Injection
CVE-2009-0324
BibCiter 1.4 - SQL Injection via idp, idc, or idu Parameter
CVE-2009-0302
PHP-Nuke <8.1.0.3.5b - SQL Injection
CVE-2009-0299
Groone GLinks 2.1 - SQL Injection via Cat Parameter
CVE-2009-0297
ClickAuction - SQL Injection via txtEmail or txtPassword Parameter
CVE-2009-0296
Script Toko Online 5.01 - SQL Injection
CVE-2009-0295
ITLPoll 2.7 Stable 2 - SQL Injection via id Parameter
CVE-2009-0293
Wazzum Dating Software - SQL Injection
CVE-2009-0292
SHOP-INET 4 - SQL Injection via show_cat2.php grid Parameter
CVE-2009-0287
KEEP Toolkit <2.5.1 - SQL Injection
CVE-2009-0284
Flax Article Manager 1.1 - SQL Injection
CVE-2009-0281
WarHound Walking Club - SQL Injection
CVE-2009-0279
Pardal CMS <0.2.0 - SQL Injection
CVE-2009-0252
Enthrallweb eReservations - SQL Injection
CVE-2009-0121
Goople CMS 1.8.2 - SQL Injection via Password Parameter
CVE-2009-0111
Goople CMS < 1.8.2 - SQL Injection via Username Parameter
CVE-2009-0110
riotpix < 0.61 - SQL Injection via ForumID Parameter
CVE-2009-0109
riotpix < 0.61 - SQL Injection via Username Parameter
CVE-2009-0106
phpauctions - SQL Injection via profile.php user_id Parameter
Details
Vulnerabilities
19,944
Exploit Likelihood
High