CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,944 vulnerabilities with CWE-89
CVE-2008-6364
Ad Server Solutions Banner Exchange Solution Java - SQL Injection via Logon Process
CVE-2008-6362
Multiple Membership Script 2.5 - SQL Injection via id Parameter
CVE-2008-6358
Social Groupie - SQL Injection via id Parameter
CVE-2008-6353
ASP-CMS 1.0 - SQL Injection via cha Parameter
CVE-2008-6352
Xpoze Pro 4.10 - SQL Injection via Menu Parameter
CVE-2008-6350
TurnkeyForms Local Classifieds - SQL Injection via listtest.php r Parameter
CVE-2008-6349
TurnkeyForms Business Survey Pro 1.0 - SQL Injection via id Parameter
CVE-2008-6348
DevelopItEasy Photo Gallery 1.2 - SQL Injection via cat_id, photo_id, user_name, or user_pass Parameter
CVE-2008-6345
SolarCMS 0.53.8 and 1.0 - SQL Injection via Forum.php cat Parameter
CVE-2008-6344
TYPO3 TU-Clausthal Staff < 0.3.0 - SQL Injection
CVE-2008-6338
WEBERkommunal Facilities 2.0 - SQL Injection
CVE-2008-6337
Volunteer Management System (com_volunteer) 2.0 - SQL Injection via job_id Parameter
CVE-2008-6333
RSS Simple News - SQL Injection via pid Parameter
CVE-2008-6332
Simple Customer 1.2 - SQL Injection via Login Password Parameter
CVE-2008-6330
MyTopix < 1.3.0 - Authenticated SQL Injection via Notes Action Send Parameter
CVE-2008-6329
Pre ASP Job Board - SQL Injection via Username or Password Parameter
CVE-2008-6328
Butterfly Organizer 2.0.0 and 2.0.1 - SQL Injection via id Parameter
CVE-2008-6327
ProQuiz 1.0 - SQL Injection via Password Parameter
CVE-2008-6326
Simple Customer - SQL Injection via Email Parameter
CVE-2008-6324
CF_Forum - SQL Injection via categorynbr Parameter
CVE-2008-6323
CFMSource CF_Auction - SQL Injection via forummessages.cfm categorynbr Parameter
CVE-2008-6322
CFMSource CFMBlog - SQL Injection via categorynbr Parameter
CVE-2008-6320
CF Shopkart 5.2.2 - SQL Injection via Category Parameter
CVE-2008-6319
CF_Calendar - SQL Injection via calid Parameter
CVE-2008-6314
phpBB Tag Board < 4.0 - SQL Injection via id Parameter
Details
Vulnerabilities
19,944
Exploit Likelihood
High