CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,952 vulnerabilities with CWE-89
CVE-2008-5595
ASP AutoDealer - SQL Injection via ID Parameter
CVE-2008-5590
Kalptaru Infotech Product Sale Framework 0.1 - SQL Injection
CVE-2008-5589
Katy Whitton RankEm - SQL Injection
CVE-2008-5588
Katy Whitton RankEm - SQL Injection
CVE-2008-5586
Check Up New Generation <4.52 - SQL Injection
CVE-2008-5582
Nukedit 4.9.x - SQL Injection via Email Parameter
CVE-2008-5578
scssboard 1.0-1.12 - SQL Injection via Multiple Parameters
CVE-2008-5574
Webmaster Marketplace - SQL Injection
CVE-2008-5573
Poll Pro 2.0 - SQL Injection via Login Username or Password Parameter
CVE-2008-5571
Professional Download Assistant 0.1 - SQL Injection
CVE-2008-5561
Netref 4.0 - SQL Injection via id Parameter
CVE-2008-5559
PostEcards - SQL Injection via cid Parameter
CVE-2008-5496
PozScripts Business Directory Script - SQL Injection
CVE-2008-5494
Joomla! com_contactinfo 1.0 - SQL Injection
CVE-2008-5493
PHPStore Wholesales - SQL Injection
CVE-2008-5491
slimcms < 1.0.0 - SQL Injection via edit.php pageID Parameter
CVE-2008-5490
PHPStore Yahoo Answers - SQL Injection
CVE-2008-5489
ClipShare Pro <2008 - SQL Injection
CVE-2008-5488
E-topbiz Domain Shop 2 - SQL Injection
CVE-2008-5486
TurnkeyForms Text Link Sales - SQL Injection
CVE-2008-5434
PunBB 1.3-1.3.1 - Authenticated SQL Injection via admin/users.php or admin/settings.php Parameters
CVE-2008-5365
ActiveWebSoftwares ActiveVotes <2.2 - SQL Injection
CVE-2008-5337
Bandwebsite 1.5 - SQL Injection
CVE-2008-5336
WebStudio CMS - SQL Injection via pageid Parameter
CVE-2008-5335
PHP-Fusion 6.01.15/7.00.1 - SQL Injection
Details
Vulnerabilities
19,952
Exploit Likelihood
High