CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,999 vulnerabilities with CWE-89
CVE-2007-0794
GlobalMegaCorp dvddb 0.6 - SQL Injection
CVE-2007-0695
Free LAN In(tra|ter)net Portal <1.0-RC3 - SQL Injection
CVE-2007-0642
tForum 2.00 - SQL Injection via id or pass Parameter
CVE-2007-0582
chernobile 1.0 - SQL Injection via User Field
CVE-2007-0520
Unique Ads 1.x - SQL Injection via Banner bid Parameter
CVE-2007-0527
Website Baker < 2.6.5 - SQL Injection via REMEMBER_KEY Cookie Parameter
CVE-2007-0350
SmE FileMailer < 1.21 - SQL Injection via ps, us, f, or code Parameter
CVE-2007-0196
motionborg_web_real_estate < 2.1 - SQL Injection via txtUserName Parameter
CVE-2006-7247
Joomla com_weblinks < 1.0.9 - SQL Injection via Title Parameter
CVE-2006-7170
Koan Software Mega Mall - SQL Injection via Multiple Parameters
CVE-2006-7138
Oracle APEX < 2.1 - Authenticated SQL Injection via wwv_flow_utilities.gen_popup_list P_LOV Parameter
CVE-2006-7116
Kubix < 0.7 - SQL Injection via member_id Parameter
CVE-2006-7118
DMXReady Site Engine Manager 1.0 - SQL Injection via mid Parameter
CVE-2006-7089
Ban 0.1 - SQL Injection via id Parameter
CVE-2006-7025
Bookmark4U < 2.1 - SQL Injection via admin/config.php sqlcmd Parameter
CVE-2006-6848
ASPTicker 1.0 - SQL Injection via admin.asp PATH_INFO
CVE-2006-6880
php-update < 2.7 - SQL Injection via newmessage, newname, newwebsite, or newemail Parameter
CVE-2006-6912
phpmyfaq < 1.6.7 - SQL Injection
CVE-2006-7231
Civica Software Civica - SQL Injection via display.asp Entry Parameter
CVE-2006-7232
MySQL 5.0.x < 5.0.32 and 5.1.x < 5.1.14 - Authenticated Denial of Service via EXPLAIN SELECT FROM INFORMATION_SCHEMA
CVE-2006-6747
dreaxteam xt-news 0.1 - SQL Injection via id_news Parameter
CVE-2006-6706
Soumu Workflow and Koukyoumuke Soumu Workflow - Authenticated SQL Injection
CVE-2006-6402
MyStats < 1.0.8 - SQL Injection via Details Parameter
CVE-2006-6367
DUware DUdownload <1.1 - SQL Injection
CVE-2006-6337
Aspee/Dogantepe Ziyaretci Defteri - SQL Injection
Details
Vulnerabilities
19,999
Exploit Likelihood
High