CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
19,999 vulnerabilities with CWE-89
CVE-2006-6349
PWP Technologies The Classified Ad System - SQL Injection
CVE-2006-6157
ContentNow < 1.39 - SQL Injection via PageID Parameter
CVE-2006-6109
CandyPress Store 3.5.2.14 - SQL Injection via Policy or Brand Parameter
CVE-2006-6094
ActiveNews Manager - SQL Injection via catID, articleID, or query Parameter
CVE-2006-6095
ActiveNews Manager - SQL Injection via articleID or page Parameter
CVE-2006-6073
Enthrallweb eShopping Cart - SQL Injection via ProductID or CategoryID Parameter
CVE-2006-6038
pForum < 1.29a - SQL Injection via editpoll.php id Parameter
CVE-2006-6048
Etomite CMS 0.6.1.2 - SQL Injection via id Parameter
CVE-2006-5957
infinicart - SQL Injection via groupid, productid, catid, or subid Parameter
CVE-2006-5840
Abarcar Realty Portal - SQL Injection via newsdetails.php neid or slistl.php slid Parameter
CVE-2006-5829
AIOCP < 1.3.007 - SQL Injection via Multiple Parameters
CVE-2006-5738
HIGH
PunBB < 1.2.14 - Authenticated SQL Injection
CVSS 7.2
CVE-2006-5629
Hosting Controller < 6.1 Hotfix 3.3 - SQL Injection via ForumID Parameter
CVE-2006-5606
bytesfall_explorer < 0.0.7.1 - SQL Injection via Username Parameter
CVE-2006-5603
CRITICAL
Snitz Forums 2000 3.4.06 - SQL Injection via RC Parameter
CVSS 9.8
CVE-2006-5242
Etomite < 0.6.1 - SQL Injection
CVE-2006-5221
Cahier de texte 2.0 - SQL Injection via matiere_ID or classe_ID Parameter
CVE-2006-4785
moodle < 1.6.1 - SQL Injection via Blog Format Parameter
CVE-2006-4734
Tikiwiki 1.9.4 - SQL Injection via pid or where Parameter
CVE-2006-4736
CMS.R. 5.5 - SQL Injection via adminname or adminpass Parameter
CVE-2006-4756
phpMyDirectory <10.4.6 - SQL Injection
CVE-2006-4564
Simplemachines Smf - SQL Injection
CVE-2006-4214
Zen Cart < 1.3.0.2 - SQL Injection via GPC Data and Session ID
CVE-2006-4064
YenerTurk Haber Script <= 2.0 - SQL Injection via id Parameter
CVE-2006-4042
mybloggie < 2.1.4 - SQL Injection via trackback.php Parameters
Details
Vulnerabilities
19,999
Exploit Likelihood
High