CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,965 vulnerabilities with CWE-89
CVE-2008-3554
Discuz! 6.0.1 - SQL Injection via searchid Parameter
CVE-2008-3556
Battle.net Clan Script 1.5.2 - SQL Injection
CVE-2008-3507
LiteNews 0.1 - SQL Injection via id Parameter
CVE-2008-3512
PHP-Nuke Kleinanzeigen Module - SQL Injection via lid Parameter
CVE-2008-3513
Book Catalog module 1.0 - SQL Injection
CVE-2008-3495
Pcshey Portal - SQL Injection via kategori.asp kid Parameter
CVE-2008-3497
MyPHP CMS 0.3.1 - SQL Injection via pid Parameter
CVE-2008-3498
nBill (com_netinvoice) 1.2.0 SP1 - SQL Injection
CVE-2008-3506
polypager < 1.0 - SQL Injection via nr Parameter
CVE-2008-3487
PHPAuction GPL Enhanced 2.51 - SQL Injection
CVE-2008-3489
PHPX 3.5.16 - SQL Injection via PXL Cookie in checkCookie Function
CVE-2008-3490
E-topbiz Online Dating <3.0 - SQL Injection
CVE-2008-3491
Scripts24 iPost <1.0.1, iTGP <1.0.4 - SQL Injection
CVE-2008-3484
eStoreAff 0.1 - SQL Injection via cid Parameter
CVE-2008-3452
eNdonesia Calendar module - SQL Injection via loc_id Parameter
CVE-2008-3445
phpMyRealty 2.0.0 - SQL Injection via Location Parameter
CVE-2008-3412
Comsenz EPShop <3.0 - SQL Injection
CVE-2008-3413
Greatclone GC Auction Platinum - SQL Injection
CVE-2008-3414
SiteAdmin <line2.php - SQL Injection
CVE-2008-3416
IceBB - SQL Injection via Username Parameter in Members Module
CVE-2008-3417
fipsCMS light < 2.1 - SQL Injection via r Parameter
CVE-2008-3418
willo trio < 2.1 - SQL Injection via browse.php id Parameter
CVE-2008-3419
Youtuber Clone - SQL Injection via UID Parameter
CVE-2008-3420
Mobius for Mimsy XG <1.4.4.1 - SQL Injection
CVE-2008-3393
BookMine - SQL Injection via events_id Parameter
Details
Vulnerabilities
19,965
Exploit Likelihood
High