CWE-89
High likelihoodImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
20,010 vulnerabilities with CWE-89
CVE-2005-0252
BibORB 1.3.2 - SQL Injection via Username or Password
CVE-2005-1017
MaxWebPortal < 1.33 - SQL Injection via EVENT_ID Parameter
CVE-2005-0413
MyPHP Forum 1.0 - SQL Injection via forum.php fid Parameter
CVE-2004-1553
aspWebAlbum - SQL Injection via Username Field or Cat Parameter
CVE-2004-2695
vBulletin 3.0-3.0.3 - SQL Injection via Authorize.net Callback x_invoice_num Parameter
CVE-2004-2716
PHPMyChat 0.14.5 - SQL Injection via usersL.php3 Parameters
CVE-2004-2737
NetSupport DNA HelpDesk 1.01 - SQL Injection via problist.asp where Parameter
CVE-2004-2746
Pensacola WEB Designs Xtremeasp Photogallery - SQL Injection
CVE-2004-2751
PostNuke 0.726 - SQL Injection via Members List Sortby Parameter
CVE-2004-2754
YaBB SE - SQL Injection via ID_MEMBER Parameter
CVE-2004-1339
Oracle Database Server - SQL Injection via MDSYS.SDO_GEOM_TRIG_INS1 or MDSYS.SDO_LRS_TRIG_INS Triggers
CVE-2004-0366
libpam-pgsql <0.5.2 - SQL Injection
CVE-2004-1925
Tiki CMS/Groupware < 1.8.1 - SQL Injection via sort_mode or offset Parameter
CVE-2003-1598
WordPress < 0.7 - SQL Injection via Posts Variable
CVE-2003-1573
SUN J2ee - SQL Injection
CVE-2003-1244
phpBB 2.0-2.0.2 - SQL Injection via forum_id Parameter
CVE-2003-1340
PHP-Nuke 5.6 and 6.5 - Authenticated SQL Injection via uid Cookie and aid Cookie
CVE-2003-1435
PHP-Nuke 5.6 and 6.0 - SQL Injection via Search Module Days Parameter
CVE-2003-1458
ttCMS and ttForum 2.2 - SQL Injection via Profile.php Member Name Parameter
CVE-2003-1504
Goldlink 3.0 - SQL Injection via vadmin_login or vadmin_pass Cookie
CVE-2003-1520
Fuzzymonkey My Classifieds 2.11 - SQL Injection via Email Parameter
CVE-2003-1523
dbmail 1.1 - SQL Injection via IMAP Daemon Login Username or Mailbox Name
CVE-2003-1530
phpBB <= 2.0.3 - SQL Injection via privmsg.php mark[] Parameter
CVE-2003-1532
PhpMyShop 1.00 - SQL Injection via Identifiant or Password Parameter
CVE-2003-1533
PhpPass 2 - SQL Injection via uid and pwd Parameters
Details
Vulnerabilities
20,010
Exploit Likelihood
High