CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,999 vulnerabilities with CWE-89
CVE-2007-5490
Okul Otomasyon Portal 2.0 - SQL Injection via id Parameter
CVE-2007-5485
KwsPHP mg2 1.0 - SQL Injection via Album Parameter
CVE-2007-5458
KwsPHP Newsletter Module 1.0 - SQL Injection via Newsletter Parameter
CVE-2007-5449
Softbiz Recipes Portal Script - SQL Injection via sbcat_id Parameter
CVE-2007-5452
php-stats 0.1.9.2 - SQL Injection via ip or t Parameter
CVE-2007-5430
Stride CMS 1.0 - SQL Injection via p Parameter or id Parameter or course Parameter or provider Parameter
CVE-2007-5408
cpDynaLinks 1.02 - SQL Injection via Category Parameter
CVE-2007-5371
Modxcms - SQL Injection
CVE-2007-5372
SQL-Ledger 2.x - SQL Injection via Invoice Quantity or Sort Field
CVE-2007-5316
Softbiz Jobs and Recruitment Script - SQL Injection via browsecats.php cid Parameter
CVE-2007-5308
PHP Homepage M 1.0 - SQL Injection via Galerie.php ID Parameter
CVE-2007-5272
Furkan Tastan Blog - SQL Injection via kategori.asp id Parameter
CVE-2007-5261
MultiCart 1.0 - SQL Injection via catid or ddlCategory Parameter
CVE-2007-5233
Web Template Management System 1.3 - SQL Injection via id Parameter
CVE-2007-5220
ASP Product Catalog - SQL Injection via cid Parameter
CVE-2007-5222
MAXdev MDPro 1.0.76 - SQL Injection via Referer Header
CVE-2007-5177
MambAds < 1.5 - SQL Injection via caid Parameter
CVE-2007-5180
Ohesa Emlak Portali - SQL Injection via Kategori or Emlak Parameter
CVE-2007-5181
Netkamp Emlak Scripti - SQL Injection via detay.asp ilan_id Parameter
CVE-2007-5187
PHP-Fusion Expanded Calendar Module - SQL Injection via sel Parameter
CVE-2007-5189
x-script GuestBook 1.3a - SQL Injection via name/email/icq/website Parameters
CVE-2007-5084
BrightStor Hierarchical Storage Manager < 11.5 - SQL Injection via CsAgent Service Commands
CVE-2007-5150
NukeSentinel 2.5.11 - SQL Injection via Base64-Encoded Admin Cookie
CVE-2007-5151
NukeSentinel 2.5.12 - SQL Injection via Base64-Encoded Admin Cookie
CVE-2007-5141
SiteX CMS 0.7.3 Beta - SQL Injection via Search Parameter
Details
Vulnerabilities
19,999
Exploit Likelihood
High