CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,988 vulnerabilities with CWE-89
CVE-2008-0430
360 Web Manager 3.0 - SQL Injection via IDFM Parameter
CVE-2008-0421
Invision Gallery < 2.0.7 - SQL Injection via Album Parameter
CVE-2008-0397
aflog 1.01 - SQL Injection via Comments ID Parameter
CVE-2008-0388
WP-Forum 1.7.4 - SQL Injection via User Parameter in Showprofile Action
CVE-2008-0371
aliTalk 1.9.1.1 - SQL Injection via mohit, id, or username Parameter
CVE-2008-0383
MyBB < 1.2.10 - Authenticated SQL Injection via Moderation and Admin Parameters
CVE-2008-0353
php-residence 0.7.2 and 1.0 - SQL Injection via cognome_cerca Parameter
CVE-2008-0355
phpecho_cms < 2.0-rc3 - SQL Injection via Forum Module id Parameter
CVE-2008-0358
Pixelpost 1.7 - SQL Injection via parent_id Parameter
CVE-2008-0360
BLOG:CMS 4.2.1b - SQL Injection via blogid, user, or field Parameter
CVE-2008-0363
clever_copy < 3.0 - SQL Injection via ID Parameter or Album Parameter
CVE-2008-0325
FaScript FaPersian Petition - SQL Injection via show.php id Parameter
CVE-2008-0326
FaScript FaPersianHack 1.0 - SQL Injection via id Parameter
CVE-2008-0327
FaScript FaMp3 1.0 - SQL Injection via show.php id Parameter
CVE-2008-0328
FaScript FaName 1.0 - SQL Injection via id Parameter
CVE-2008-0291
RichStrong CMS - SQL Injection via showproduct.asp cat Parameter
CVE-2008-0288
ImageAlbum 2.0.0b2 - SQL Injection via id Parameter
CVE-2008-0290
digitalhive < 2.0_rc2 - SQL Injection via selectskin Parameter
CVE-2008-0286
Article Dashboard - SQL Injection via Admin Login User or Password Fields
CVE-2008-0280
MTCMS 2.0 - SQL Injection via a or cid Parameter
CVE-2008-0281
ID-Commerce < 2.0 - SQL Injection via idFamille Parameter
CVE-2008-0282
domphp < 0.81 - SQL Injection via Mail Parameter
CVE-2008-0173
Gforge < 4.6.99 - SQL Injection via RSS Export Parameters
CVE-2008-0253
Binn SBuilder - SQL Injection via full_text.php nid Parameter
CVE-2008-0254
TutorialCMS 1.02 - SQL Injection via activate.php userName Parameter
Details
Vulnerabilities
19,988
Exploit Likelihood
High