CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,954 vulnerabilities with CWE-89
CVE-2008-5222
dvbbs 8.2.0 - SQL Injection via login.asp Username Parameter
CVE-2008-5216
AJ Square ZeusCart <2.0 - SQL Injection
CVE-2008-5215
ClanLite 2.2006.05.20 - SQL Injection
CVE-2008-5213
AJ Article 1.0 - SQL Injection via artid Parameter
CVE-2008-5212
AJ Auction <= 6.2.1 - SQL Injection via item_id Parameter
CVE-2008-5208
com_datsogallery 1.6 - SQL Injection via User-Agent HTTP Header
CVE-2008-5200
Joomla com_xewebtv - SQL Injection via id Parameter
CVE-2008-5198
Acmlmboard 1.A2 - SQL Injection via Memberlist pow Parameter
CVE-2008-5197
php-fusion - SQL Injection via Classifieds Detail Adverts lid Parameter
CVE-2008-5196
Kroax (the_kroax) 4.42 - SQL Injection
CVE-2008-5195
SebracCMS 0.4 - SQL Injection via recid Parameter
CVE-2008-5194
SoftVisions obm 2.2 - SQL Injection
CVE-2008-5192
Philboard 1.14 and 1.2 - SQL Injection via forum.asp forumid Parameter
CVE-2008-5191
SePortal 2.4 - SQL Injection via poll_id or sp_id Parameter
CVE-2008-5190
eshop100 - SQL Injection via SUB Parameter
CVE-2008-5174
Jokes Complete Website 2.1.3 - SQL Injection
CVE-2008-5170
Cheats Complete Website 1.1.1 - SQL Injection
CVE-2008-5169
Drinks Complete Website 2.1.0 - SQL Injection
CVE-2008-5168
Tips Complete Website 1.2.0 - SQL Injection
CVE-2008-5166
Riddles Website 1.2.1 - SQL Injection
CVE-2008-5165
eTicket 1.5.7 - SQL Injection via pri Parameter
CVE-2008-5163
The Rat CMS Pre-Alpha 2 - SQL Injection
CVE-2008-5132
MemHT Portal 4.0.1 - SQL Injection via X-Forwarded-For Header
CVE-2008-5131
Develop It Easy News And Article System 1.4 - SQL Injection via aid Parameter and Admin Panel Credentials
CVE-2008-5123
CCleague Pro 1.2 - SQL Injection via admin.php u Parameter
Details
Vulnerabilities
19,954
Exploit Likelihood
High