CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2008-6477
Mumbojumbo Op4 - SQL Injection
CVE-2008-6475
Drake CMS < 0.2.2.846 - SQL Injection via HTTP_VIA Header
CVE-2008-6471
MountainGrafix easyLink 1.1.0 - SQL Injection via detail.php cat Parameter
CVE-2008-6469
PlainCart 1.1.2 - SQL Injection via Index.php p Parameter
CVE-2008-6468
Diesel Pay - SQL Injection via Area Parameter in Browse Action
CVE-2008-6467
Diesel Job Site - SQL Injection via job_id Parameter
CVE-2008-6466
Akira Powered Image Gallery 0.9.6.2 - SQL Injection via Image Parameter
CVE-2008-6464
Basic PHP Events Lister 1.0 - SQL Injection via event.php id Parameter
CVE-2008-6463
pd_churchsearch < 0.2.10 - SQL Injection
CVE-2008-6462
My quiz and poll (myquizpoll) < 0.1.4 - SQL Injection
CVE-2008-6461
Random Prayer 2 < 0.0.2 - SQL Injection
CVE-2008-6460
mw_random_objects < 1.0.3 - SQL Injection
CVE-2008-6459
TYPO3 auto BE User Registration < 0.0.2 - SQL Injection
CVE-2008-6458
FE address edit for tt_address & direct mail < 0.4.0 - SQL Injection
CVE-2008-6457
cgswigmore < 0.1.2 - SQL Injection
CVE-2008-6456
HBook < 2.3.0 - SQL Injection
CVE-2008-6454
6rbscript 3.3 - SQL Injection via singerid Parameter
CVE-2008-6452
oceandir < 2.9 - SQL Injection via show_vote.php id Parameter
CVE-2008-6451
jPORTAL 2 - SQL Injection via humor.php id Parameter
CVE-2008-6443
phpkf - SQL Injection via forum_duzen.php fno Parameter
CVE-2008-6438
MacGuru BLOG Engine Plugin 2.1.4-2.2 - SQL Injection via uid Parameter
CVE-2008-6434
Blue River Sava CMS < 5.0 - SQL Injection via LinkServID Parameter
CVE-2008-6430
Joomla com_mycontent 1.1.13 - SQL Injection via id Parameter
CVE-2008-6429
com_prayercenter < 1.4.9 - SQL Injection via id Parameter
CVE-2008-6427
hivemaker < 1.0.2 - SQL Injection via cid Parameter
Details
Vulnerabilities
19,944
Exploit Likelihood
High