CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,968 vulnerabilities with CWE-89
CVE-2008-2872
shibby_shop < 2.2 - SQL Injection via sayfa Parameter
CVE-2008-2874
Softbiz Jokes & Funny Pics Script - SQL Injection via sbjoke_id Parameter
CVE-2008-2875
Webdevindo-CMS 1.0.0 - SQL Injection via hal Parameter
CVE-2008-2843
doitlive/cms < 2.50 - SQL Injection via ID Parameter or Licence Cookie
CVE-2008-2844
carscripts_classifieds - SQL Injection via cat Parameter
CVE-2008-2845
MyBizz-Classifieds - SQL Injection via cat Parameter
CVE-2008-2846
BoatScripts Classifieds - SQL Injection via Type Parameter
CVE-2008-2847
Maxtrade AIO 1.3.23 - SQL Injection via Trade Module categori Parameter
CVE-2008-2850
Drupal Trailscout Module - SQL Injection
CVE-2008-2853
Easy Webstore 1.2 - SQL Injection via cat_path Parameter
CVE-2008-2856
OwnRS Beta 3 - SQL Injection via clanek.php id Parameter
CVE-2008-2858
WebChamado 1.1 - SQL Injection via eml Parameter
CVE-2008-2860
AJSquare AJ Auction Pro 2.0 - SQL Injection via category.php cate_id Parameter
CVE-2008-2862
eLineStudio Site Composer < 2.6 - SQL Injection via id or template_id Parameter
CVE-2008-2865
PHP Site Lock 2.0 - SQL Injection via articleid Parameter
CVE-2008-2866
CaupoShop Classic 1.3 - SQL Injection via saArticle[ID] Parameter
CVE-2008-2834
Scientific Image DataBase 0.41 - SQL Injection via projects.php id Parameter
CVE-2008-2835
IGSuite 3.2.4 - SQL Injection via formid Parameter
CVE-2008-2837
CMS-BRD - SQL Injection via Menuclick Parameter
CVE-2008-2815
MyMarket 1.72 - SQL Injection via Shopping Index ID Parameter
CVE-2008-2816
Oxygen 2.0 - SQL Injection via repquote Parameter
CVE-2008-2817
nitro_web_gallery < 1.4.3 - SQL Injection via CatId Parameter
CVE-2008-2819
BlognPlus < 2.5.4 - SQL Injection
CVE-2008-2823
PHPeasyblog < 1.13 - SQL Injection via Newsarchive Post Parameter
CVE-2008-2789
basic-cms - SQL Injection via page_id Parameter
Details
Vulnerabilities
19,968
Exploit Likelihood
High