CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,951 vulnerabilities with CWE-89
CVE-2008-6100
Discussion Forums 2k 3.3 - SQL Injection
CVE-2008-6069
123flashchat echat_plugin 4.2 - SQL Injection via Nick Parameter
CVE-2008-6068
Joomla! com_joomladate 1.2 - SQL Injection
CVE-2008-6093
Noname CMS 1.0 - SQL Injection via file_id or kategorie Parameter
CVE-2008-6091
BMForum 5.6 - SQL Injection via Tagname Parameter
CVE-2008-6088
com_joomtracker 1.01 - SQL Injection via id Parameter
CVE-2008-6086
Camera Life 2.6.2b4 - SQL Injection
CVE-2008-6081
Simple Customer 1.2 - SQL Injection
CVE-2008-6078
Limbo CMS com_privmsg - SQL Injection via id Parameter
CVE-2008-6077
LoudBlog <= 0.8.0a - Authenticated SQL Injection via colpick Parameter
CVE-2008-6076
Joomla! com_dailymessage 1.0.3 - SQL Injection
CVE-2008-6075
Bahar Download Script 2.0 - SQL Injection
CVE-2008-6064
DomPHP 0.81 - SQL Injection via Agenda Cat Parameter
CVE-2008-6050
Joomla! com_tech_article 1.0 - SQL Injection
CVE-2008-6046
ADbNewsSender <1.5.2 - SQL Injection
CVE-2008-6043
PHP Pro Bid 6.04 - SQL Injection via Order Field and Order Type Parameters
CVE-2008-6042
NetArtMedia Real Estate Portal 2.0 - SQL Injection
CVE-2008-6040
Arcadem Pro 2.700-2.802 - SQL Injection via articlecat Parameter
CVE-2008-6038
MapCal 0.1 - SQL Injection via id Parameter in editevent Action
CVE-2008-6037
AvailScript Article Script - SQL Injection
CVE-2008-6033
WSN Links 2.20 - SQL Injection via Comments.php ID Parameter
CVE-2008-6032
WSN Links Free 4.0.34P - SQL Injection
CVE-2008-6031
WSN Links 2.22, 2.23, 2.34 - SQL Injection via vote.php id Parameter
CVE-2008-6030
NetArtMedia Jobs Portal 1.3 - SQL Injection
CVE-2008-6029
buzzywall <= 1.3.1 - SQL Injection via Search Parameter
Details
Vulnerabilities
19,951
Exploit Likelihood
High