CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,952 vulnerabilities with CWE-89
CVE-2008-5959
Active Test 2.1 - SQL Injection via Useremail or Password Parameter
CVE-2008-5958
Active Test 2.1 - SQL Injection via QuizID Parameter
CVE-2008-5957
Joomla! com_mydyngallery 1.4.2 - SQL Injection
CVE-2008-5955
PHPSTREET Webboard 1.0 - SQL Injection via show.php id Parameter
CVE-2008-5954
KTP Computer Customer Database - SQL Injection via lname Parameter
CVE-2008-5952
KTP Computer Customer Database - Authenticated SQL Injection via tid Parameter
CVE-2008-5950
ASP Template Creature - Media Level < SQL Injection
CVE-2008-2384
mod_auth_mysql - SQL Injection via Multibyte Character Set Bypass
CVE-2008-5946
php-fusion 4.01 - SQL Injection via News ID Parameter
CVE-2008-5940
MODx <0.9.6.2 - SQL Injection
CVE-2008-5934
CMS ISWEB 3.0 - SQL Injection via id_sezione Parameter
CVE-2008-5930
The Net Guys ASPired2Blog - SQL Injection
CVE-2008-5928
Free Links Directory Script 1.2a - SQL Injection
CVE-2008-5927
FlexPHPNews 0.0.6 - SQL Injection via User Check Parameters
CVE-2008-5926
ASP-DEv Internal E-Mail System - SQL Injection
CVE-2008-5924
ASP-DEv XM Events Diary - SQL Injection
CVE-2008-5923
ASP-DEv XM Events Diary - SQL Injection
CVE-2008-5921
Umer Inc Songs Portal - SQL Injection
CVE-2008-5895
Mediatheka 4.2 - SQL Injection via User Parameter
CVE-2008-5892
ClickAndEmail - SQL Injection via ID Parameter or Admin Credentials
CVE-2008-5890
injader < 2.1.2 - SQL Injection via id Parameter
CVE-2008-5888
Click&Rank - SQL Injection via id or userid or PassWord Parameter
CVE-2008-5882
Citrix Application Gateway - Broadcast Server <6.1 - SQL Injection
CVE-2008-5877
Phpclanwebsite <1.23.3.5 - SQL Injection
CVE-2008-5875
com_lowcosthotels - SQL Injection via id Parameter
Details
Vulnerabilities
19,952
Exploit Likelihood
High