CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
20,009 vulnerabilities with CWE-89
CVE-2006-0959
MyBulletinBoard 1.03-1.04 - SQL Injection via Cookie Parameter
CVE-2006-0961
Cilem Hiber 1.1 - SQL Injection via haber_id Parameter
CVE-2006-0897
VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 - SQL Injection via UpdateID0 Parameter
CVE-2006-0772
Hitachi Business Logic 02-03-03-00-/B - SQL Injection via Extended Receiving Box Function
CVE-2006-0750
supersmashbrothers Army System 2.1.0 - SQL Injection via userstat Parameter
CVE-2006-0692
Carey Briggs PHP/MYSQL Timesheet 1 and 2 - SQL Injection via yr, month, day, or job Parameters
CVE-2006-0602
phphg Guestbook 1.2 - SQL Injection via Username or ID Parameter
CVE-2006-0586
Oracle 10g Release 1 - SQL Injection via Multiple Parameters in SYS.KUPV$FT and SYS.KUPV$FT_INT Packages
CVE-2006-0510
Daffodil CRM 1.5 - SQL Injection via userlogin.jsp
CVE-2006-0412
CyberShop - SQL Injection via Username Parameter
CVE-2006-0413
NewsPHP - SQL Injection via discuss, tim, id, last, or limit Parameter
CVE-2006-0403
e-moBLOG 1.3 - SQL Injection via index.php monthy Parameter or admin/index.php login Parameter
CVE-2006-0318
BlogPHP 1.0 - SQL Injection via Username Parameter
CVE-2006-0269
Oracle Database 10.1.0.5 and 10.2.0.1 - SQL Injection in DBMS_CDC_PUBLISH SET_DIRECTORY_ROOT
CVE-2006-0249
BitDamaged geoBlog MOD_1.0 - SQL Injection via viewcat.php cat Parameter
CVE-2006-0240
Simple Blog < 2.1 - SQL Injection via Month Parameter
CVE-2006-0199
Mini-Nuke CMS System < 1.8.2 - SQL Injection via news.asp hid Parameter
CVE-2006-0205
Wordcircle 2.17 - SQL Injection via Login Password Field
CVE-2006-0192
ASPSurvey 1.10 - SQL Injection via Login Password Parameter
CVE-2006-0159
Foro Domus 2.10 - SQL Injection via Email Parameter
CVE-2006-0160
Venom Board 1.22 - SQL Injection via parent root or topic_id Parameters
CVE-2006-0146
ADOdb for PHP < 4.70 - Unauthenticated SQL Injection via server.php sql Parameter
CVE-2006-0115
OnePlug CMS - SQL Injection via Press_Release_ID, Service_ID, or Product_ID Parameter
CVE-2006-0123
ADN Forum 1.0b - SQL Injection via fid or pagid Parameter
CVE-2006-0074
PHPenpals < 1.1 - SQL Injection via profile.php personalID Parameter
Details
Vulnerabilities
20,009
Exploit Likelihood
High