CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,968 vulnerabilities with CWE-89
CVE-2008-2667
Courier Authentication Library < 0.60.6 - SQL Injection via Username Parameter
CVE-2008-3025
plx Ad Trader 3.2 - SQL Injection via adid Parameter
CVE-2008-3026
OneClick CMS 2008-01-24 - SQL Injection via id Parameter
CVE-2008-3027
VanGogh Web CMS 0.9 - SQL Injection via article_ID Parameter
CVE-2008-3030
EfesTECH Shop 2.0 - SQL Injection via cat_id Parameter
CVE-2008-3034
rss_aggregator 1.0 - SQL Injection via IdFlux or IdTag Parameter
CVE-2008-3035
xchangeboard < 1.70 - Authenticated SQL Injection via newThread.php boardID Parameter
CVE-2008-3038
Address Directory < 0.2.10 - SQL Injection
CVE-2008-3039
TYPO3 DAM Frontend Extension < 0.1.0 - SQL Injection
CVE-2008-3044
News Calendar Extension < 1.0.7 - SQL Injection
CVE-2008-3051
TYPO3 Pinboard Extension < 0.0.6 - SQL Injection
CVE-2008-3053
TYPO3 SQL Frontend Extension < 1.0.11 - SQL Injection
CVE-2008-3054
Branchenbuch Extension < 0.8.1 - SQL Injection
CVE-2008-3055
TYPO3 Support view extension < 0.0.102 - SQL Injection
CVE-2008-3056
TYPO3 codeon_petition_extension < 0.0.2 - SQL Injection
CVE-2008-2995
PHPEasyData 1.5.4 - SQL Injection via Annuaire Parameter or Admin Login Username
CVE-2008-2996
Gravity Board X 2.0 Beta - SQL Injection via searchquery or board_id Parameter
CVE-2008-2999
Drupal Aggregation module 5.x < 5.x-4.4 - SQL Injection
CVE-2008-2963
MyBlog - SQL Injection via View Parameter or ID Parameter
CVE-2008-2964
ResearchGuide 0.5 - SQL Injection via id Parameter
CVE-2008-2968
Academic Web Tools < 1.4.2.8 - SQL Injection via rating.php book_id Parameter
CVE-2008-2971
CiBlog 3.1 - SQL Injection via id Parameter
CVE-2008-2972
KbLance - SQL Injection via cat_id Parameter
CVE-2008-2983
Demo4 CMS 01 Beta - SQL Injection via id Parameter
CVE-2008-2989
HoMaP-CMS 0.1 - SQL Injection via Index.php Go Parameter
Details
Vulnerabilities
19,968
Exploit Likelihood
High