CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,965 vulnerabilities with CWE-89
CVE-2008-3787
Web Directory Script <2.0 - SQL Injection
CVE-2008-3788
PICTURESPRO Photo Cart 3.9 - SQL Injection
CVE-2008-3767
phpBazar 2.0.2 - SQL Injection via adid Parameter
CVE-2008-3768
Turnkey Web Tools SunShop <4.1.5 - SQL Injection
CVE-2008-3772
Pars4u Videosharing - SQL Injection
CVE-2008-3774
Simasy CMS - SQL Injection via id Parameter
CVE-2008-3748
Active PHP Bookmarks <1.2.06 - SQL Injection
CVE-2008-3749
YourFreeWorld Banner Mgr < - SQL Injection
CVE-2008-3750
YourFreeWorld URL Rotator Script - SQL Injection
CVE-2008-3751
YourFreeWorld Short Url & Url Tracker Script - SQL Injection
CVE-2008-3752
YourFreeWorld Ad-Exchange Script - SQL Injection
CVE-2008-3753
YourFreeWorld Programs Rating Script - SQL Injection
CVE-2008-3754
YourFreeWorld Stylish Text Ads Script - SQL Injection
CVE-2008-3755
YourFreeWorld Classifieds Script - SQL Injection
CVE-2008-3756
YourFreeWorld Viral Marketing Script - SQL Injection
CVE-2008-3757
YourFreeWorld Forced Matrix Script - SQL Injection
CVE-2008-3762
Turnkey PHP Live Helper <2.0.1 - SQL Injection
CVE-2008-3765
Quick Poll Script - SQL Injection via id Parameter
CVE-2008-3718
cyberBB 0.6 - Authenticated SQL Injection via id or user Parameter
CVE-2008-3719
SFS Affiliate Directory - SQL Injection
CVE-2008-3720
DMCMS 0.7.4 - SQL Injection via Page Parameter
CVE-2008-3722
fipsCMS 2.1 - SQL Injection via forum/neu.asp kat Parameter
CVE-2008-3724
papoo < 3.7.2 - SQL Injection via suchanzahl Parameter
CVE-2008-3725
YourFreeWorld Ad Board Script - SQL Injection
CVE-2008-3706
zeejobsite 2.0 - SQL Injection via bannerclick.php adid Parameter
Details
Vulnerabilities
19,965
Exploit Likelihood
High