CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,973 vulnerabilities with CWE-89
CVE-2008-1425
Easy-Clanpage 2.2 - SQL Injection via Gallery Module id Parameter
CVE-2008-1426
KAPhotoservice - SQL Injection via album.asp albumid Parameter
CVE-2008-1427
Joobi Acajoom <1.1.5,1.2.5 - SQL Injection
CVE-2008-1430
ASPapp - SQL Injection via CatId Parameter
CVE-2008-1398
AuraCMS 2.0-2.2.1 - SQL Injection via X-Forwarded-For Header
CVE-2008-1404
Viso (Industry Book) <2.04-2.03 - SQL Injection
CVE-2008-1406
eXV2 MyAnnonces 1.8 - SQL Injection via lid Parameter
CVE-2008-1407
eXV2 WebChat 1.60 - SQL Injection via roomid Parameter
CVE-2008-1408
phpbp 2 RC3 (2.204) FIX 4 - SQL Injection via Banner ID Parameter
CVE-2008-1354
Advanced Data Solutions VSO-XP - SQL Injection
CVE-2008-1341
LaGarde StoreFront <6 - SQL Injection
CVE-2008-1344
MyioSoft EasyCalendar <4.0tr - SQL Injection
CVE-2008-1346
MyioSoft EasyGallery <5.0tr - SQL Injection
CVE-2008-1349
bamaGalerie 3.03-3.041 - SQL Injection
CVE-2008-1350
Fully Modded phpBB 80220 - SQL Injection
CVE-2008-1351
XOOPS Tutorials 2.1b - SQL Injection via tid Parameter
CVE-2008-1336
Koobi CMS 4.2.3-4.3.0 - SQL Injection via Categ Parameter
CVE-2008-1315
ZClassifieds - SQL Injection via Cat Parameter
CVE-2008-1316
QT-cute QuickTalk Forum <1.6 - SQL Injection
CVE-2008-1295
phpMyNewsletter <0.8 beta 5 - SQL Injection
CVE-2008-1297
eWriting 1.2.1 - SQL Injection via cat Parameter
CVE-2008-1298
Hadith module for PHP-Nuke - SQL Injection via cat Parameter
CVE-2008-1305
Filebase mod for phpBB - SQL Injection
CVE-2008-1308
Sudirman Angriawan NukeC30 3.0 - SQL Injection
CVE-2008-1313
Bloo < 1.0 - SQL Injection via post_id Parameter
Details
Vulnerabilities
19,973
Exploit Likelihood
High