CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,968 vulnerabilities with CWE-89
CVE-2008-2901
Haudenschilt Family Connections CMS 1.4 - Authenticated SQL Injection via addressbook.php address Parameter
CVE-2008-2902
AlstraSoft AskMe Pro < 2.1 - SQL Injection via Profile ID Parameter
CVE-2008-2903
Advanced Webhost Billing System 2.3.3-2.7.1 - SQL Injection via News.php Viewnews Parameter
CVE-2008-2904
phpmycart - SQL Injection via shop.php cat Parameter
CVE-2008-2906
WebChamado 1.1 - SQL Injection via tsk_id Parameter
CVE-2008-2907
WebChamado 1.1 - SQL Injection via eml Parameter
CVE-2008-2909
Clever Copy 3.0 - SQL Injection via Search Type Parameter
CVE-2008-2914
PHP JOBWEBSITE PRO - SQL Injection via JobSearch3.php kw or position Parameter
CVE-2008-2915
Pre Job Board - SQL Injection via JobSearch.php Position or Keyword Parameter
CVE-2008-2916
Pre ADS Portal < 2.0 - SQL Injection via cid or id Parameter
CVE-2008-2917
E-SMART CART - SQL Injection via category_id Parameter
CVE-2008-2918
Cartweaver 3.0 - SQL Injection via details.php prodId Parameter
CVE-2008-2919
Gryphon gllcTS2 4.2.4 - SQL Injection via listing.php sort Parameter
CVE-2008-2921
EZCMS < 1.2 - SQL Injection via Page Parameter
CVE-2008-2925
Webmatic < 2.8 - SQL Injection
CVE-2008-2890
Online Fantasy Football League <= 0.2.6 - SQL Injection via fflteam_id, league_id, or player_id Parameter
CVE-2008-2891
emusoft emuCMS 0.3 - SQL Injection via cat_id Parameter
CVE-2008-2892
EXP Shop Component 1.0 for Joomla! - SQL Injection via catid Parameter
CVE-2008-2893
AJ Square aj-hyip - SQL Injection via news.php id Parameter
CVE-2008-2897
PageSquid CMS 0.3 Beta - SQL Injection via Page Parameter
CVE-2008-2900
PHPAuction 3.2 - SQL Injection via item.php id Parameter
CVE-2008-2867
E-topbiz Viral DX 1 2.07 - SQL Injection via adclick.php bannerid Parameter
CVE-2008-2868
DUcalendar < 1.0 - SQL Injection via iEve Parameter
CVE-2008-2869
E-topbiz Link ADS 1 - SQL Injection via linkid Parameter
CVE-2008-2870
ShareCMS 0.1 Beta - SQL Injection via eventID or userID Parameter
Details
Vulnerabilities
19,968
Exploit Likelihood
High