CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,965 vulnerabilities with CWE-89
CVE-2008-4044
AJ Square aj-hyip - SQL Injection via artid Parameter
CVE-2008-4043
AJ Square AJ HYIP Acme - SQL Injection
CVE-2008-4039
spice_classifieds - SQL Injection via cat_path Parameter
CVE-2008-3965
MyBB < 1.4.1 - SQL Injection via Editor Field
CVE-2008-3955
Masir Camp E-Shop Module <3.0 - SQL Injection
CVE-2008-3954
AlstraSoft Forum Pay Per Post Exchange - SQL Injection
CVE-2008-3953
Vastal I-Tech Shaadi Zone 1.0.9 - SQL Injection
CVE-2008-3952
EsFaq 2.0 - SQL Injection via idcat Parameter
CVE-2008-3951
Vastal I-Tech Agent Zone - SQL Injection
CVE-2008-3948
XRMS CRM - SQL Injection via admin/users/self-2.php
CVE-2008-3942
Full PHP Emlak Script - SQL Injection
CVE-2008-3943
eZoneScripts Living Local 1.1 - SQL Injection
CVE-2008-3944
ACG-PTP 1.0.6 - SQL Injection via adid Parameter
CVE-2008-3945
Words tag 1.2 - SQL Injection via Word Parameter in Claim Action
CVE-2008-3918
Ovidentia 6.6.5 - SQL Injection via Search Field Parameter
CVE-2008-3880
ZoneMinder < 1.23.3 - SQL Injection via Filter Array Parameter
CVE-2008-3887
dotProject 2.1.2 - Authenticated SQL Injection via Tab or User_ID Parameter
CVE-2008-3888
Mini-NUKE Freehost 2.3 - SQL Injection
CVE-2008-3861
phpMyRealty < 1.0.9 - SQL Injection via id or price_max Parameter
CVE-2008-3845
Crafty Syntax Live Help <2.14.6 - SQL Injection
CVE-2008-3848
Z-Breaknews 2.0 - SQL Injection via id Parameter
CVE-2008-3780
Five Star Review Script - SQL Injection
CVE-2008-3783
Matterdaddy Market 1.1 - SQL Injection
CVE-2008-3784
BtiTracker <1.4.7, xBtiTracker <2.0.542 - SQL Injection
CVE-2008-3785
MiaCMS 4.6.5 - SQL Injection via com_content id Parameter
Details
Vulnerabilities
19,965
Exploit Likelihood
High