CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,962 vulnerabilities with CWE-89
CVE-2008-4436
bBlog 0.7.6 - SQL Injection via mod Parameter
CVE-2008-4433
RMSOFT MiniShop module 1.0 - SQL Injection via search.php itemsxpag Parameter
CVE-2008-4431
IceBB < 1.0-rc9.3 - SQL Injection via Skin Parameter
CVE-2008-4423
Ovidentia 6.6.5 - SQL Injection via Item Parameter in Contact Modify Action
CVE-2008-4379
Hot Links SQL-PHP < 3.0 - Cross-Site Scripting via report.php id Parameter
CVE-2008-4378
Hot Links SQL-PHP < 3.0 - SQL Injection via Report ID Parameter
CVE-2008-4377
Creator CMS 5.0 - SQL Injection via sideid Parameter
CVE-2008-4376
Live TV Script - SQL Injection via mid Parameter
CVE-2008-4375
Availscript Classmate Script - SQL Injection via viewprofile.php p Parameter
CVE-2008-4374
CMS Buzz - SQL Injection via id Parameter in playgame Action
CVE-2008-4373
AvailScript Job Portal Script - SQL Injection via jid Parameter
CVE-2008-4371
AvailScript Article Script - SQL Injection via aIDS Parameter
CVE-2008-4369
Availscript Photo Album - SQL Injection via sid Parameter
CVE-2008-4364
ParsaGostar ParsaWeb CMS - SQL Injection via id or txtSearch Parameter
CVE-2008-4357
Powie pLink 2.07 - SQL Injection via id Parameter
CVE-2008-4356
Kasseler CMS 1.1.0 and 1.2.0 - SQL Injection via Multiple Parameters
CVE-2008-4355
Powie PSCRIPT Forum <= 1.30 - SQL Injection via showprofil.php id Parameter
CVE-2008-4354
NetArt Media iBoutique 4.0 - SQL Injection via Cat Parameter
CVE-2008-4353
Linkarity - SQL Injection via cat_id Parameter
CVE-2008-4352
phpSmartCom 0.2 - SQL Injection via UID Parameter
CVE-2008-4350
vbLOGIX Tutorial Script < 1.0 - SQL Injection via cat_id Parameter
CVE-2008-4348
PHPortfolio - SQL Injection via photo.php id Parameter
CVE-2008-4347
Powie pNews 2.03 - SQL Injection via newsid Parameter
CVE-2008-4345
WebPortal CMS < 0.7.4 - SQL Injection via download.php aid Parameter
CVE-2008-4344
6rbscript - SQL Injection via CatID Parameter
Details
Vulnerabilities
19,962
Exploit Likelihood
High