CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,991 vulnerabilities with CWE-89
CVE-2007-6602
noserub < 0.5.2 - SQL Injection via Login Username Field
CVE-2007-6565
Blakord Portal <1.3.A - SQL Injection
CVE-2007-6566
XZero Community Classifieds <4.95.11 - SQL Injection
CVE-2007-6575
MMSLamp - SQL Injection via idpro Parameter
CVE-2007-6576
Adult Script <1.6.5 - SQL Injection
CVE-2007-6577
zBlog 1.2 - SQL Injection via categ or article Parameter
CVE-2007-6578
PHP ZLink 0.3 - SQL Injection via id Parameter
CVE-2007-6579
Ip Reg 0.3 - SQL Injection via vlan_id Parameter
CVE-2007-6580
Wallpaper Site 1.0.09 - SQL Injection
CVE-2007-6583
1024 CMS 1.3.1 - SQL Injection via IP Parameter
CVE-2007-6586
nicLOR-CMS - SQL Injection via sezione_news.php id Parameter
CVE-2007-6587
Plogger 1.0 Beta 3.0 - SQL Injection
CVE-2007-6543
eSyndiCat Link Exchange Script - SQL Injection
CVE-2007-6544
RunCMS - SQL Injection via lid Parameter
CVE-2007-6551
MailMachine Pro <2.2.6 - SQL Injection
CVE-2007-6556
websihirbazi 5.1.1 - SQL Injection via News ID or Page ID Parameter
CVE-2007-6557
MeGaCheatZ 1.1 - SQL Injection via ItemID Parameter
CVE-2007-6559
Logaholic - SQL Injection via from or page Parameter
CVE-2007-6538
MRBS - SQL Injection via id Parameter
CVE-2007-6540
neuron news 1.0 - SQL Injection via q Parameter
CVE-2007-6517
Eagle Software Aeries Browser Interface <3.7.9.17 - SQL Injection
CVE-2007-6518
WoltLab Burning Board (wBB) Lite 1.0.2 pl3e - SQL Injection
CVE-2007-6472
phpMyRealty 1.0.9 - SQL Injection via Search Type Parameter
CVE-2007-6484
phpRPG 0.8 - SQL Injection via Password Parameter
CVE-2007-6491
Kvaliitti WebDoc 3.0 CMS - SQL Injection
Details
Vulnerabilities
19,991
Exploit Likelihood
High