CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,999 vulnerabilities with CWE-89
CVE-2007-4808
TLM CMS 3.2 - SQL Injection via Multiple Parameters
CVE-2007-4810
Netjuke 1.0-rc2 - SQL Injection via ge_id or id Parameter
CVE-2007-4777
Joomla! 1.5 before RC2 - SQL Injection
CVE-2007-4778
Joomla! 1.5 Beta1-1.5 RC1 - SQL Injection via Content Component Filter Parameter
CVE-2007-4762
e-smart_cart 1.0 - SQL Injection via User and Pass Fields
CVE-2007-3913
Gforge < 3.0 - SQL Injection
CVE-2007-4736
CartKeeper CKGold Shopping Cart 2.0 - SQL Injection via category_id Parameter
CVE-2007-4714
Yvora 1.0 - SQL Injection via ID Parameter
CVE-2007-4716
PHD Help Desk < 1.31 - SQL Injection
CVE-2007-4719
212cafeBoard 6.30 Beta - SQL Injection via read.php id Parameter
CVE-2007-4653
phpBB Links MOD < 1.2.2 - SQL Injection via Start Parameter
CVE-2007-4634
Cisco CallManager/CUCM <3.3.5sr2b-4.3.1sr1 - SQL Injection
CVE-2007-4602
Implied by Design Micro CMS <3.5 - SQL Injection
CVE-2007-4603
ACG News 1.0 - SQL Injection via aid or catid Parameter
CVE-2007-4604
DL PayCart 1.01 - SQL Injection via ItemID Parameter
CVE-2007-4611
Dale Mooney Gallery - SQL Injection via viewevent.php id Parameter
CVE-2007-4597
TurnkeyWebTools SunShop <4.0 RC 6 - SQL Injection
CVE-2007-4581
WBB2-Addon: Acrotxt <1 - SQL Injection
CVE-2007-4552
Agares Media Arcadem 2.01 - SQL Injection
CVE-2007-4540
Olate Download (od) <3.4.2 - SQL Injection
CVE-2007-4491
Gurur haber 2.0 - SQL Injection via id Parameter
CVE-2007-4456
Mambo SimpleFAQ Component - SQL Injection via aid Parameter
CVE-2007-4368
IBM Rational ClearQuest <7.0.0.2 - SQL Injection
CVE-2007-4258
Prozilla Pub Site Directory - SQL Injection
CVE-2007-4207
Gallery In A Box - SQL Injection via Username or Password Field
Details
Vulnerabilities
19,999
Exploit Likelihood
High