CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2008-6795
nicLOR Vibro-School-CMS - SQL Injection via nID Parameter
CVE-2008-6794
Scripts For Sites EZ Pub Site - SQL Injection via cat Parameter
CVE-2008-6789
MindDezign Photo Gallery 2.2 - SQL Injection via Username Parameter
CVE-2008-6788
MindDezign Photo Gallery 2.2 - SQL Injection via id Parameter
CVE-2008-6787
Lizardware CMS < 0.6.0 - SQL Injection via Administrator Index User Parameter
CVE-2008-6784
Scripts For Sites EZ Adult Directory - SQL Injection via cat_id Parameter
CVE-2008-6783
Sites for Scripts EZ Home Business Directory - SQL Injection via cat_id Parameter
CVE-2008-6782
ez_hosting_directory - SQL Injection via cat_id Parameter
CVE-2008-6781
Sites for Scripts Gaming Directory - SQL Injection via cat_id Parameter
CVE-2008-6780
Scripts for Sites EZ Affiliate - SQL Injection via cat_id Parameter
CVE-2008-6779
PHP-Nuke Sarkilar Module - SQL Injection via id Parameter
CVE-2008-6778
Scripts for Sites EZ Auction - SQL Injection via viewfaqs.php cat Parameter
CVE-2008-6777
MyPHP Forum < 3.0 - SQL Injection via Member and Post Parameters
CVE-2008-6776
Scripts For Sites EZ Hot or Not - SQL Injection via viewcomments.php phid Parameter
CVE-2008-6753
SilverStripe < 2.2.2 - SQL Injection via AjaxUniqueTextField
CVE-2008-6749
FlexPHPDirectory 0.0.1 - SQL Injection via checkuser or checkpass Parameters
CVE-2008-6741
Simple Machines Forum < 1.1.4 - SQL Injection via db_character_set Parameter
CVE-2008-6730
FlexPHPLink Pro 0.0.6 and 0.0.7 - SQL Injection via Usercheck Parameters
CVE-2008-6728
PHP-Nuke < 7.9 - SQL Injection via Sections Module artid Parameter
CVE-2008-6725
CMScout 2.06 - Authenticated SQL Injection via id Parameter
CVE-2008-6721
AJ Square AJ Article - SQL Injection via txtName Parameter
CVE-2008-6720
DeltaScripts PHP Links < 1.3 - SQL Injection via admin_username Parameter
CVE-2008-6697
michael_fritz/worldcup < 2.0.0 - SQL Injection
CVE-2008-6696
Fussballtippspiel (toto) <= 0.1.1 - SQL Injection
CVE-2008-6695
timtab_sociable < 2.0.4 - SQL Injection
Details
Vulnerabilities
19,944
Exploit Likelihood
High