CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,951 vulnerabilities with CWE-89
CVE-2008-6230
Pre Podcast Portal - SQL Injection via Tour.php id Parameter
CVE-2008-6227
Pre Multi-Vendor Shopping Malls - SQL Injection via buyer_detail.php sid/cid Parameters
CVE-2008-6226
Pre Projects PHP Auto Listings Script - SQL Injection via moreinfo.php itemno Parameter
CVE-2008-6225
Mole Group Airline Ticket Sale Script - SQL Injection via info.php flight parameter
CVE-2008-6220
Simple Document Management System 1.1.4-1.1.5 - SQL Injection via Login Password Parameter
CVE-2008-6216
Venalsur Booking Centre Booking System for Hotels Group - SQL Injection via OfertaID Parameter
CVE-2008-6214
Harlandscripts Pro Traffic One - SQL Injection via poll_results.php id Parameter
CVE-2008-6213
Harlandscripts Pro Traffic One - SQL Injection via trg Parameter in mypage.php
CVE-2008-6163
OpenX 2.6.1 - SQL Injection via BannerID Parameter
CVE-2008-6210
dream4 Koobi 4.4 and 5.4 - SQL Injection via img_id Parameter
CVE-2008-6209
Vastal I-Tech Software Zone - SQL Injection via view_product.php cat_id Parameter
CVE-2008-6204
SuperNET Shop < 1.0 - SQL Injection via id, kulad, sifre, username, or password Parameters
CVE-2008-6203
CoBaLT 2.0 - SQL Injection via id Parameter
CVE-2008-6202
CoBaLT 1.0 - SQL Injection via id Parameter
CVE-2008-6198
Custom Pages 1.0 plugin for MyBulletinBoard - SQL Injection via Page Parameter
CVE-2008-6197
KwsPHP galerie_module - SQL Injection via id_gal Parameter
CVE-2008-6189
GForge 4.5.19 - SQL Injection via Offset Parameter
CVE-2008-6188
Gforge < 4.6rc1 - SQL Injection via skill_edit[] Parameter
CVE-2008-6187
Gforge < 4.5.19 - SQL Injection via release_id Parameter
CVE-2008-6184
OwnBiblio 1.5.3 - SQL Injection via catid Parameter
CVE-2008-6182
Joomla Ignitegallery - SQL Injection
CVE-2008-6181
com_mad4joomla < 1.1.8.2 - SQL Injection via jid Parameter
CVE-2008-6180
NewLife Blogger < 3.0 - SQL Injection via nlb3 Cookie
CVE-2008-6179
IndexScript 3.0 - SQL Injection via sug_cat.php parent_id Parameter
CVE-2008-6166
jmds com_kbase 1.2 - SQL Injection via id Parameter
Details
Vulnerabilities
19,951
Exploit Likelihood
High