CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
20,009 vulnerabilities with CWE-89
CVE-2006-2760
4nForum 0.91 - SQL Injection via tid Parameter
CVE-2006-2416
e107 <= 0.7.2 - SQL Injection via Cookie Parameter
CVE-2006-2363
Limbo CMS - SQL Injection via Weblinks catid Parameter
CVE-2006-2301
OzzyWork Galeri - SQL Injection via Login or Password Fields
CVE-2006-2239
Newsadmin 1.1 - SQL Injection via readarticle.php nid Parameter
CVE-2006-2259
MaxxSchedule 1.0 - SQL Injection via Logon.asp txtLogon Parameter
CVE-2006-2268
FlexCustomer <= 0.0.6 - SQL Injection via checkuser/checkpass or username/password Parameters
CVE-2006-2157
Plogger Beta 2.1 - SQL Injection via Gallery ID Parameter
CVE-2006-2128
Pro Publish 2.0 - SQL Injection via Email, Password, Find String, Article ID, or Category ID Parameters
CVE-2006-2090
MySmartBB 1.1.x - SQL Injection via misc.php id or username Parameter
CVE-2006-2103
Mybulletinboard - SQL Injection
CVE-2006-1978
FlexBB < 0.5.5 - SQL Injection via flexbb_username Cookie Parameter
CVE-2006-1962
pcpin_chat 5.0.4 - SQL Injection via Username Field
CVE-2006-1871
Oracle Database Server 9.2.0.7 and 10.1.0.5 - SQL Injection via DBMS_LOGMNR_SESSION DELETE_FROM_TABLE Function
CVE-2006-1751
MvBlog - SQL Injection
CVE-2006-1676
MAXdev MDPro <1.076 - SQL Injection
CVE-2006-1500
Tilde CMS 3.0 - SQL Injection via id Parameter
CVE-2006-1501
OneOrZero 1.6.3.0 - SQL Injection via id Parameter
CVE-2006-1423
UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2 and earlier - SQL Injection via Number Parameter
CVE-2006-1360
MusicBox 2.3 Beta 2 - SQL Injection
CVE-2006-1330
phpwebsite <= 0.83 - SQL Injection via sid Parameter
CVE-2006-1278
@1 File Store <2006.03.07 - SQL Injection
CVE-2006-1049
Joomla! < 1.0.7 - Authenticated SQL Injection
CVE-2006-1018
DCI-Designs Dawaween 1.03 - SQL Injection via id Parameter
CVE-2006-1006
Sendcard < 3.2.3 - SQL Injection
Details
Vulnerabilities
20,009
Exploit Likelihood
High