CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,971 vulnerabilities with CWE-89
CVE-2008-2634
I-Pos Internet Pay Online Store < 1.3 - SQL Injection via Item Parameter
CVE-2008-2560
427BB 2.3.1 - SQL Injection via showpost.php post Parameter
CVE-2008-2562
PowerPhlogger < 2.2.5 - Authenticated SQL Injection via css_str Parameter
CVE-2008-2564
JotLoader < 1.2.1.a - SQL Injection via cid Parameter
CVE-2008-2565
php-address_book < 4.0 - SQL Injection via id Parameter
CVE-2008-2568
Joomla com_simpleshop < 3.4 - SQL Injection via catid Parameter
CVE-2008-2569
Joomla EasyBook Component 1.1 - SQL Injection via gbid Parameter
CVE-2008-2572
FlashBlog - SQL Injection via articulo_id Parameter
CVE-2008-2554
BP Blog 6.0 - SQL Injection via id or cat Parameter
CVE-2008-2555
EasyWay CMS - SQL Injection via mid Parameter
CVE-2008-2556
PHP Visit Counter < 0.4 - SQL Injection via read.php datespan Parameter
CVE-2008-2231
Slashcode Slash <= R_2_5_0_94 - SQL Injection via id Parameter
CVE-2008-2521
YABSoft Mega File Hosting Script 1.2 - Authenticated SQL Injection via fid Parameter
CVE-2008-2522
Battle.net Clan Script < 1.5.3 - SQL Injection via showmember Parameter
CVE-2008-2523
RakNet Autopatcher Server < 3.23 - SQL Injection
CVE-2008-2529
Advanced Links Management 1.5.2 - SQL Injection via catId Parameter
CVE-2008-2530
QuickUpCMS - SQL Injection via Multiple Parameters
CVE-2008-2532
AJ Square aj-hyip - SQL Injection via forum/topic_detail.php id Parameter
CVE-2008-2535
Phoenix View CMS Pre Alpha2 and earlier - SQL Injection via del Parameter
CVE-2008-2536
YABSoft Advanced Image Hosting Script < 2.1 - SQL Injection via out.php t Parameter
CVE-2008-2537
HispaH Model Search - SQL Injection via cat Parameter
CVE-2008-2501
PHPhotoalbum 0.5 - SQL Injection via Album or PID Parameter
CVE-2008-2504
Simpel Side Netbutik 1-4 - SQL Injection via cat or id Parameter
CVE-2008-2506
Simpel Side Weblosning 1-4 - SQL Injection via mainid or id Parameter
CVE-2008-2509
excuse_online - SQL Injection via pwd.asp pID Parameter
Details
Vulnerabilities
19,971
Exploit Likelihood
High