CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,999 vulnerabilities with CWE-89
CVE-2007-4173
Hunkaray Okul Portali 1.1 - SQL Injection
CVE-2007-4095
BSM Store Dependent Forums 1.02 - SQL Injection
CVE-2007-4056
Prozilla Adult Directory - SQL Injection
CVE-2007-3933
QuickEStore < 8.2 - SQL Injection via CFTOKEN Parameter
CVE-2007-3937
a-shop < 0.70 - SQL Injection
CVE-2007-3938
MAXdev MDPro < 1.0.8x - SQL Injection via Topics Module topicid Parameter
CVE-2007-3909
Bandersnatch 0.4 - SQL Injection via Date and Limit Parameters
CVE-2007-3884
husrevforum 1.0.1 and 2.0.1 - SQL Injection via forumid Parameter
CVE-2007-3705
FuseTalk 2.0 - SQL Injection via FTVAR_SUBCAT Parameter
CVE-2007-3687
RPG Inferno < 2.4 - Authenticated SQL Injection via id Parameter
CVE-2007-3677
Maxsi eVisit Analyst - SQL Injection via id Parameter
CVE-2007-3637
MKPortal 1.1.1 - SQL Injection
CVE-2007-3563
AV Arcade 2.1b - SQL Injection via id Parameter
CVE-2007-3539
QuickTalk Forum 1.3 and QuickTicket 1.2 build:20070621 - SQL Injection via Multiple Parameters
CVE-2007-3447
BugMall Shopping Cart 2.5 - SQL Injection via Basic Search Box
CVE-2007-3399
Power Phlogger < 2.2.5 - SQL Injection via Username Parameter
CVE-2007-3301
FuseTalk - SQL Injection via errorcode Parameter
CVE-2007-3273
FuseTalk 2.0 - SQL Injection
CVE-2007-3119
Kartli Alisveris Sistemi 1.0 - SQL Injection via news.asp news_id Parameter
CVE-2007-3063
My Databook - SQL Injection via Diary Delete Parameter
CVE-2007-2997
SalesCart Shopping Cart - SQL Injection via Password Field
CVE-2007-2898
2z_project 0.9.5 - SQL Injection via Rating Parameter
CVE-2007-2803
Vizayn Urun Tanitim Sitesi 0.2 - SQL Injection
CVE-2007-2673
Censura < 1.16.04 - SQL Injection via vendorid Parameter
CVE-2007-2571
wfquotes_module < 1.0.0 - SQL Injection via index.php c Parameter
Details
Vulnerabilities
19,999
Exploit Likelihood
High