CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,988 vulnerabilities with CWE-89
CVE-2008-0511
Joomla! and Mambo com_mamml - SQL Injection via listid Parameter
CVE-2008-0512
Joomla com_fq - SQL Injection via listid Parameter
CVE-2008-0514
Joomla Glossary Component - SQL Injection via catid Parameter
CVE-2008-0515
Joomla and Mambo musepoes Component - SQL Injection via aid Parameter
CVE-2008-0517
Mambo - SQL Injection via EstateAgent Component objid Parameter
CVE-2008-0518
com_recipes - SQL Injection via id Parameter
CVE-2008-0519
com_jokes - SQL Injection via CatView Cat Parameter
CVE-2008-0520
WassUp Plugin 1.4-1.4.3 - SQL Injection via from_date or to_date Parameter
CVE-2008-0487
ASPired2Protect - SQL Injection via Username and Password Parameters
CVE-2008-0490
WP-Cal Plugin 0.3 - SQL Injection via id Parameter
CVE-2008-0491
fGallery 2.4.1 - SQL Injection via Album Parameter
CVE-2008-0498
Bigware Shop 2.0 - SQL Injection via pollid Parameter
CVE-2008-0499
Mambo LaiThai 4.5.5 - SQL Injection
CVE-2008-0468
flinx < 1.3 - SQL Injection via category.php id Parameter
CVE-2008-0469
Tiger Php News System < 1.0b - SQL Injection via catid Parameter
CVE-2008-0461
PHP-Nuke < 8.0_final - SQL Injection via Search Module sid Parameter
CVE-2008-0446
LulieBlog 1.02 - SQL Injection via voircom.php id Parameter
CVE-2008-0447
Foojan WMS PHP Weblog 1.0 - SQL Injection via Story Parameter
CVE-2008-0449
VP-ASP Shopping Cart <= 6.50 - SQL Injection via paypalresult.asp
CVE-2008-0451
PacerCMS 0.6 - Authenticated SQL Injection via id Parameter
CVE-2008-0453
Easysitenetwork Recipe - SQL Injection via categoryid Parameter
CVE-2008-0422
boastmachine < 3.1 - SQL Injection via mail.php id Parameter
CVE-2008-0424
Mooseguy Blog System 1.0 - SQL Injection via blog.php month Parameter
CVE-2008-0428
bloofoxCMS 0.3 - SQL Injection via Username or Password Parameter
CVE-2008-0429
AlstraSoft Forum Pay Per Post Exchange 2.0 - SQL Injection via catid Parameter
Details
Vulnerabilities
19,988
Exploit Likelihood
High