CWE-89

High likelihood

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Parent: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

20,009 vulnerabilities with CWE-89
CVE-2005-4891 CRITICAL
Simple Machine Forum <1.0.4 - SQL Injection
CVSS 9.8
CVE-2005-4606
Web Wiz Database Login <1.71, Journal <1.0, Site News <3.06, Weekly Poll <3.06 - SQL Injection
CVE-2005-4617
cSupport < 1.0 - SQL Injection via tickets.php pg Parameter
CVE-2005-4632
Vote! Pro < 4.0 - SQL Injection via poll_frame.php poll_id Parameter
CVE-2005-4711
Neocrome Land Down Under 801 - SQL Injection via HTTP Referer Header
CVE-2005-4515
lois_software webdb < 1.1 - SQL Injection via Search Parameters
CVE-2005-4500
MusicBox 2.3 - SQL Injection via Show or Type Parameter
CVE-2005-4478
papoo < 2.1.2 - SQL Injection via menuid forumid or reporeid_print Parameter
CVE-2005-4495
SpireMedia mx7 - SQL Injection via cid Parameter
CVE-2005-4380
Bitweaver 1.1-1.1.1 beta - SQL Injection
CVE-2005-4382
CitySoft Community Enterprise 4.x - SQL Injection
CVE-2005-4349 MEDIUM
phpMyAdmin 2.7.0 - Authenticated SQL Injection via dbname or checkprivs Parameters
CVSS 6.3
CVE-2005-4315
Plexum PLEXCART X3 < 3.0 - SQL Injection via Search Function
CVE-2005-4263
Envolution - SQL Injection via News Module startrow or catid Parameter
CVE-2005-4228
phpwebgallery < 1.7.2 - SQL Injection via Multiple Parameters
CVE-2005-4232
jamit_job_board < 2.4.1 - SQL Injection via cat Parameter
CVE-2005-4244
Snipe Gallery < 3.1.4 - SQL Injection via Gallery ID or Image ID Parameter
CVE-2005-4246
Plogger Beta 2 - SQL Injection via id or page Parameter
CVE-2005-4195
Scout Portal Toolkit <= 1.3.1 - SQL Injection via Multiple Parameters
CVE-2005-4198
Netref 3.0 - SQL Injection via Cat Parameter
CVE-2005-4199
MyBB < 1.0 - SQL Injection via Calendar and User Profile Parameters
CVE-2005-4071
CFMagic Magic Forum Personal < 2.5 - SQL Injection via ForumID or ThreadID Parameter
CVE-2005-4073
CFMagic Magic List Pro < 2.5 - SQL Injection via ListID Parameter
CVE-2005-4058
saralblog 1 - SQL Injection via viewprofile.php id Parameter
CVE-2005-4040
FileLister < 0.51 - SQL Injection via Search Parameters
Details
Vulnerabilities 20,009
Exploit Likelihood High