CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
20,009 vulnerabilities with CWE-89
CVE-2005-4011
Codewalkers ltwCalendar < 4.1.3 - SQL Injection via id Parameter
CVE-2005-4027
SimpleBBS 1.1 - SQL Injection via Search Module Parameters
CVE-2005-3996
Zen Cart < 1.2.6d - SQL Injection via admin_email Parameter
CVE-2005-3984
WebCalendar 1.0.1 - SQL Injection via time_range Parameter
CVE-2005-3952
PHP Labs Top Auction - SQL Injection via Category or Type Parameter
CVE-2005-3877
Simple Document Management System < 2.0-cvs - SQL Injection via folder_id or mid Parameter
CVE-2005-3881
AtlantisFAQ Knowledge Base Software < 2.03 - SQL Injection via search.php searchStr Parameter
CVE-2005-3840
Omnistar Live < 5.2 - SQL Injection via id or category_id Parameter
CVE-2005-3845
EZ Invoice Inc 2.0 - SQL Injection via invoices.php i Parameter
CVE-2005-3817
Softbiz Web Host Directory Script < 1.1 - SQL Injection via Multiple Parameters
CVE-2005-3744
phpcomasy < 0.7.5 - SQL Injection via id Parameter
CVE-2005-3748
Tru-Zone Nuke ET 3.2 - SQL Injection via Search Module Query Parameter
CVE-2005-3686
Unclassified NewsBoard < 1.5.3_patch3 - SQL Injection via DateFrom or DateUntil Parameter
CVE-2005-3646
phpAdsNew and phpPgAds 2.0.6 - SQL Injection via SessionID Parameter
CVE-2005-3543
Phorum 5.0.0alpha-5.0.20 - SQL Injection via search.php forum_ids Parameter
CVE-2005-3553
phpkit < 1.6.1 - SQL Injection via id or session Parameter
CVE-2005-3497
PHP Handicapper - SQL Injection via process_signup.php serviceid Parameter
CVE-2005-3365
DCP-Portal <= 6 - SQL Injection via register.php name parameter
CVE-2005-3325
Analysis Console for Intrusion Databases and Basic Analysis and Security Engine - SQL Injection via sig Parameter
CVE-2005-3046
phpmyfaq 1.5.1 - SQL Injection via User Field
CVE-2005-2983
Oracle Reports - SQL Injection via Lexical References Parameter Form
CVE-2005-2035
Cool Cafe Chat 1.2.1 - SQL Injection via login.asp Password Parameter
CVE-2005-1487
FishCart 3.1 - SQL Injection via cartid or psku Parameter
CVE-2005-1500
myBloggie 2.1.1 - SQL Injection via Multiple Parameters
CVE-2005-0252
BibORB 1.3.2 - SQL Injection via Username or Password
Details
Vulnerabilities
20,009
Exploit Likelihood
High