CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2008-6425
ComicShout 2.8 - SQL Injection via News ID Parameter
CVE-2008-6422
Psychostats 2.3, 2.3.1, 2.3.3 - SQL Injection via id Parameter
CVE-2008-6419
Social Site Generator 2.0 - SQL Injection via sgc_id, scm_mem_id, or catid Parameter
CVE-2008-6418
TorrentTrader - SQL Injection via scrape.php info_hash Parameter
CVE-2008-6414
AJ Auction Pro Platinum Skin 2 - SQL Injection via detail.php item_id Parameter
CVE-2008-6409
ol'bookmarks manager 0.7.5 - SQL Injection via id Parameter
CVE-2008-6405
Hotscripts Clone - SQL Injection via cid Parameter
CVE-2008-6401
jetik-web - SQL Injection via sayfa.php kat Parameter
CVE-2008-6394
CS-Cart <= 1.3.5 - SQL Injection via cs_cookies[customer_user_id] Cookie Parameter
CVE-2008-6392
Z1Exchange - SQL Injection via showads.php id Parameter
CVE-2008-6391
nexusjnr jbook - SQL Injection via User Parameter
CVE-2008-6390
Membership Manager Pro - SQL Injection via Login Password Parameter
CVE-2008-6389
Rae Media Contact Management Software - SQL Injection via Password Parameter
CVE-2008-6383
Drupal Storm < 5.x-1.14 and < 6.x-1.18 - Authenticated SQL Injection
CVE-2008-6381
bcoos 1.0.13 - Authenticated SQL Injection via cid Parameter
CVE-2008-6380
Active Web Helpdesk 2.0 - SQL Injection via CategoryID Parameter
CVE-2008-6379
Gallery MX 2.0.0 - SQL Injection via ID Parameter
CVE-2008-6378
Calendar Mx Professional 2.0.0 - SQL Injection via ID Parameter
CVE-2008-6376
Jbook - SQL Injection via Password Parameter
CVE-2008-6372
Ocean12 FAQ Manager Pro 1.0 - SQL Injection via ID Parameter in Cat Action
CVE-2008-6371
Membership Manager Pro - SQL Injection via Username Parameter
CVE-2008-6369
Ocean12 Contact Manager Pro 1.02 - SQL Injection via Sort Parameter
CVE-2008-6368
Chipmunk Guestbook 1.4m - SQL Injection via Start Parameter
CVE-2008-6366
Ad Server Solutions Affiliate Software Java 4.0 - SQL Injection via Logon.jsp Parameters
CVE-2008-6365
Ad Server Solutions Ad Management Software Java - SQL Injection via logon.jsp uname or pass Parameter
Details
Vulnerabilities
19,944
Exploit Likelihood
High