CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,987 vulnerabilities with CWE-89
CVE-2008-0752
Joomla com_neogallery 1.1 - SQL Injection via catid Parameter
CVE-2008-0753
Virtual War 1.5 - SQL Injection via Calendar Month Parameter
CVE-2008-0754
Joomla com_rapidrecipe 1.6.5 - SQL Injection via user_id or category_id Parameter
CVE-2008-0744
Pre Hotels & Resorts Management System - SQL Injection via User Login Page
CVE-2008-0733
CS Team Counter Strike Portals - SQL Injection via id Parameter
CVE-2008-0734
Limbo CMS < 1.0.4.2 - SQL Injection via cuid Cookie Parameter
CVE-2008-0735
AuraCMS 2.2 - SQL Injection via Albums Parameter
CVE-2008-0737
CandyPress 4.x and 3.x - SQL Injection via helpfield Parameter
CVE-2008-0738
CandyPress Store < 4.1 - SQL Injection via idcust or tableName Parameter
CVE-2008-0739
CandyPress < 4.1 - SQL Injection via FedExAccount Parameter
CVE-2008-0714
Mihalism Multi Host - SQL Injection via Username Parameter
CVE-2008-0719
Customer Testimonials 3 and 3.1 Addon for osCommerce - SQL Injection via testimonial_id Parameter
CVE-2008-0721
Mambo com_sermon 0.2 - SQL Injection via gid Parameter
CVE-2008-0670
Joomla com_noticias 1.0 - SQL Injection via id Parameter
CVE-2008-0675
The Everything Development Engine < pre-1.0 - SQL Injection via node_id Parameter
CVE-2008-0677
A-Blog 2 - SQL Injection via News Action ID Parameter
CVE-2008-0678
BlogPHP 2.0 - SQL Injection via id Parameter
CVE-2008-0681
PHPShop 0.8.1 - SQL Injection via index.php product_id Parameter
CVE-2008-0682
Wordspew < 3.72 - SQL Injection via id Parameter
CVE-2008-0683
ShiftThis Newsletter Plugin for WordPress - SQL Injection via Newsletter Parameter
CVE-2008-0685
iTechClassifieds 3.0 - SQL Injection via ViewCat.php CatID Parameter
CVE-2008-0686
Joomla com_neoreferences 1.3.1 and 1.3.3 - SQL Injection via catid Parameter
CVE-2008-0689
Joomla com_marketplace 1.1.1 and 1.1.1-pl1 - SQL Injection via catid Parameter
CVE-2008-0690
Joomla com_directory 2.3.2 - SQL Injection via catid Parameter
CVE-2008-0692
iTechBids 3 Gold and 5.0 - SQL Injection via bidhistory.php item_id Parameter
Details
Vulnerabilities
19,987
Exploit Likelihood
High