CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,988 vulnerabilities with CWE-89
CVE-2008-0255
iGaming CMS <= 1.3.1 - SQL Injection via Section Parameter
CVE-2008-0256
Matteo Binda ASP Photo Gallery 1.0 - SQL Injection via id or ricerca Parameter
CVE-2008-0262
Agares PhpAutoVideo 2.21 - SQL Injection via articlecat Parameter
CVE-2008-0267
eTicket 1.5.5.2 - Authenticated SQL Injection via search.php and admin.php Parameters
CVE-2008-0270
TaskFreak! < 0.6.1 - Authenticated SQL Injection via sContext Parameter
CVE-2008-0278
x7_chat < 2.0.5 - SQL Injection via Day Parameter in sm_window Action
CVE-2008-0279
Xforum 1.4 - SQL Injection via Topic Parameter
CVE-2008-0232
Zero CMS 1.0 Alpha - SQL Injection via id f or t Parameter
CVE-2008-0219
PHP Webquest 2.6 - SQL Injection via id_actividad Parameter
CVE-2008-0224
RunCMS 1.6.1 - SQL Injection via Client-Ip Parameter
CVE-2008-0185
NetRisk 1.9.7 - SQL Injection via PID Parameter
CVE-2008-0187
SAM Broadcaster samPHPweb - SQL Injection via songid Parameter
CVE-2008-0147
SmallNuke 2.0.4 - SQL Injection via User Email Parameter
CVE-2008-0154
EvilBoard 0.1a - SQL Injection via c Parameter
CVE-2008-0157
FlexBB < 0.6.3 - SQL Injection via flexbb_temp_id Cookie Parameter
CVE-2008-0159
eggblog < 3.1.0 - SQL Injection via eggblogpassword Cookie Parameter
CVE-2008-0133
Tribisur < 2.1 - SQL Injection via cat_main.php id Parameter or forum.php cat Parameter
CVE-2008-0137
SNETWORKS PHP CLASSIFIEDS 5.0 - Remote File Inclusion via path_escape Parameter
CVE-2008-0138
XOOPS mod_gallery - Remote File Inclusion via GALLERY_BASEDIR Parameter
CVE-2008-0139
loudblog < 0.8.0 - Remote Code Execution via Template Parameter
CVE-2008-0142
WebPortal CMS 0.6-beta - SQL Injection via User Name Parameter
CVE-2008-0144
NetRisk <= 1.9.7 - Remote File Inclusion via Page Parameter
CVE-2008-0129
Siteatschool < 2.3.10 - SQL Injection
CVE-2008-0130
Instant Softwares Dating Site - SQL Injection via Username Parameter
CVE-2008-0099
MyPHP Forum < 3.0 - SQL Injection via Search Parameter
Details
Vulnerabilities
19,988
Exploit Likelihood
High