CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,999 vulnerabilities with CWE-89
CVE-2007-2534
CRITICAL
phphoo3 - SQL Injection via ADMIN_USER and ADMIN_PASS Parameters
CVSS 9.8
CVE-2007-2230
CA Clever Path Portal - Authenticated SQL Injection via Search Parameters
CVE-2007-2111
Oracle Database Server 9.0.1.5, 9.2.0.7, 10.1.0.5 - Authenticated SQL Injection in SYS.DBMS_AQADM_SYS
CVE-2007-2113
Oracle Database Server - Authenticated SQL Injection in DBMS_UPGRADE_INTERNAL
CVE-2007-2000
Crea-Book < 1.0 - SQL Injection via Pseudo or Passe Parameter
CVE-2007-1960
Rha7 Downloads Module for XOOPS - SQL Injection via visit.php lid Parameter
CVE-2007-1962
WF-Snippets < 1.02 - SQL Injection via index.php c Parameter
CVE-2007-1920
SmodBIP < 1.06 - SQL Injection via Zoom Parameter
CVE-2007-1897
WordPress < 2.1.2 - Authenticated SQL Injection via XML-RPC mt.setPostCategories Method
CVE-2007-1776
DesignForJoomla.com D4J eZine < 2.8 - SQL Injection via Article Parameter
CVE-2007-1573
vBulletin 3.6.5 - Authenticated SQL Injection via Attached Before Field
CVE-2007-1548
Web Wiz Forums < 8.05 - SQL Injection via Name Parameter
CVE-2007-1469
Absolute Image Gallery 2.0 - SQL Injection via categoryid Parameter
CVE-2007-1302
LI-Guestbook 1.1 and 1.2 - SQL Injection via Country Parameter
CVE-2007-1250
ANGEL Learning Management Suite 7.1 - SQL Injection via id Parameter
CVE-2007-1154
webSPELL - SQL Injection via ws_auth Cookie
CVE-2007-1163
webSPELL < 4.01.02 - SQL Injection via printview.php topic Parameter
CVE-2007-1166
Nabopoll 1.2 - SQL Injection via result.php surv Parameter
CVE-2007-1171
NukeSentinel <2.5.12 - SQL Injection
CVE-2007-1026
xlatunes < 0.1 - SQL Injection via view.php album Parameter
CVE-2007-1034
Emporium Module < 2.3.0 - SQL Injection via category_id Parameter
CVE-2007-0984
PollMentor 2.0 - SQL Injection via id Parameter
CVE-2007-0985
phpcc < beta_4.2 - SQL Injection via nickpage.php npid Parameter
CVE-2007-0875
mcRefer - SQL Injection via install.php
CVE-2007-0789
Mambo < 4.5.4 - SQL Injection via Cancel Edit Function
Details
Vulnerabilities
19,999
Exploit Likelihood
High