CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2008-6889
ASPreferral 5.3 - SQL Injection via Merchantsadd.asp AccountID Parameter
CVE-2008-6887
Pre Classified Listings 1.0 - SQL Injection via detailad.asp siteid Parameter
CVE-2008-6883
com_livechat 1.0 - SQL Injection via last parameter to getChatRoom.php
CVE-2008-6881
com_livechat 1.0 - SQL Injection via last Parameter
CVE-2008-6880
EasySiteNetwork Free Jokes Website - SQL Injection via Joke ID Parameter
CVE-2008-6875
ASP Product Catalog - SQL Injection via cid Parameter
CVE-2008-6874
ASP SiteWare autoDealer 1 and 2 - SQL Injection via iType Parameter
CVE-2008-6873
Active Web Mail 4.0 - SQL Injection via TabOpenQuickTab1 Parameter
CVE-2008-6867
Scripts For Sites EZ Career - SQL Injection via Topic Parameter
CVE-2008-6866
PHP-Nuke Current_Issue Module - SQL Injection via id Parameter
CVE-2008-6865
PHP-Nuke Sections Module - SQL Injection via artid Parameter
CVE-2008-6853
AIST NetCat 3.0 and 3.12 - SQL Injection via PollID Parameter
CVE-2008-6852
Ice Gallery Component for Joomla! 0.5 beta 2 - SQL Injection via catid Parameter
CVE-2008-6851
PHP Link Directory 3.3 - SQL Injection via page.php name Parameter
CVE-2008-6837
Zoph 0.7.2.1 - SQL Injection
CVE-2008-6813
phpWebNews 0.2 MySQL Edition - SQL Injection via id_kat Parameter
CVE-2008-6812
phpWebNews 0.2 - SQL Injection via bukutamu.php det Parameter
CVE-2008-6810
Venalsur Booking Centre Booking System for Hotels Group 2.01 - SQL Injection via Username or Password Parameter
CVE-2008-6809
Venalsur Booking Centre Booking System for Hotels Group 2.01 - SQL Injection via HotelID Parameter
CVE-2008-6808
Scripts for Sites EZ Link Directory - SQL Injection via cat_id Parameter
CVE-2008-6805
Mic_Blog 0.0.3 - SQL Injection via cat user or site Parameter
CVE-2008-6803
Yigit Aybuga Dizi Portali - SQL Injection via diziler.asp id Parameter
CVE-2008-6802
phPhotoGallery 0.92 - SQL Injection via Username and Password Fields
CVE-2008-6798
Pre Projects Pre Real Estate Listings - SQL Injection via Username or Password Parameter
CVE-2008-6796
Pre Real Estate Listings - SQL Injection via Username Parameter
Details
Vulnerabilities
19,944
Exploit Likelihood
High