CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,962 vulnerabilities with CWE-89
CVE-2008-4628
myWebland miniBloggie 1.0 - SQL Injection via del.php post_id Parameter
CVE-2008-4627
rgallery_plugin 1.09 - SQL Injection via itemID Parameter
CVE-2008-4625
ShiftThis Newsletter - SQL Injection via Newsletter Parameter
CVE-2008-4623
DS-Syndicate 1.1.1 - SQL Injection via feed_id Parameter
CVE-2008-4621
ZeeScripts Zeeproperty - SQL Injection via bannerclick.php adid Parameter
CVE-2008-4620
MRBS < 1.4 - SQL Injection via Area Parameter
CVE-2008-4617
pyxicom actualite 1.0 - SQL Injection via id Parameter
CVE-2008-4613
PortalApp 4.0 - SQL Injection via forums.asp sortby Parameter
CVE-2008-4611
PHP Arsivimiz Php Ziyaretci Defteri - SQL Injection via Sayfa Parameter
CVE-2008-4606
IP Reg <= 0.4 - SQL Injection via location_id or vlan_id Parameter
CVE-2008-4605
easycafeengine - SQL Injection via id Parameter
CVE-2008-4604
Easy CafeEngine 1.1 - SQL Injection via itemid Parameter
CVE-2008-4603
iGaming CMS 2.0 Alpha 1 - SQL Injection via search.php keywords parameter
CVE-2008-4599
Mosaic Commerce - SQL Injection via category.php cid Parameter
CVE-2008-4590
Stash 1.0.3 - SQL Injection via Username or Post Parameter
CVE-2008-4574
Ayco Okul Portali - SQL Injection via default.asp linkid Parameter
CVE-2008-4573
MunzurSoft Web Portal W3 - SQL Injection via kategori.asp kat Parameter
CVE-2008-4570
Real Estate Classifieds - SQL Injection via cat Parameter
CVE-2008-4569
XIGLA Absolute Poll Manager XE 4.1 - SQL Injection via xlacomments.asp p Parameter
CVE-2008-4534
EC-CUBE < 2.1.2a - SQL Injection
CVE-2008-4531
Brilliant Gallery < 5.x-4.2 - SQL Injection
CVE-2008-4527
PHP-Fusion Recepies Module 1.1 - SQL Injection via kat_id Parameter
CVE-2008-4525
ampjuke 0.7.5 - SQL Injection via Special Parameter in Performerid Action
CVE-2008-4524
AdaptCMS 1.3 - SQL Injection via Check User Feature
CVE-2008-4523
IP Reg < 0.4 - SQL Injection via user_name Parameter
Details
Vulnerabilities
19,962
Exploit Likelihood
High