Vulnerabilities (CVE)

Filtered by CWE-89
Total 12892 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-3659 1 Stanback 1 Bs Counter 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in file/stats.php in BS Counter 2.5.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2008-2874 1 Softbizscripts 1 Softbiz Jokes And Funny Pics Script 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vector than CVE-2008-1050.
CVE-2008-6366 1 Adserversolutions 1 Affiliate Software Java 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.
CVE-2009-0421 1 Joomla 2 Com Eventing, Joomla 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
CVE-2008-3154 1 Webblizzard 1 Content Management System 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2008-3674 1 Pozscripts 1 Tubeguru Video Sharing Script 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execute arbitrary SQL commands via the UID parameter.
CVE-2008-4621 1 Zeescripts 1 Zeeproperty 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter.
CVE-2008-1315 1 Php-nuke 1 Zclassifieds 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter to modules.php.
CVE-2008-5751 1 Alstrasoft 1 Web Email Script Enterprise 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.
CVE-2008-5293 1 Bdigital Web Solutions 1 Webstudio Ehotel 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands via the pageid parameter.
CVE-2008-2569 1 Joomla 1 Easybook Component 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action to index.php.
CVE-2008-1763 1 Blogator Script 1 Blogator Script 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in _blogadata/include/sond_result.php in Blogator-script 0.95 allows remote attackers to execute arbitrary SQL commands via the id_art parameter.
CVE-2008-5213 1 Aj Square 1 Aj Article 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.
CVE-2009-0427 1 Dmxready 1 Member Directory Manager 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-5737 1 Nodstrum 1 Mysql Calendar 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2008-5131 1 Develop It Easy 1 News And Article System 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).
CVE-2008-3586 1 Joomla 1 Com Ezstore 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
CVE-2009-3665 1 Nullam 1 Nullam Blog 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) i parameter or (2) v parameters in a register action.
CVE-2009-0431 1 Codefixer 1 Linkspro 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter.
CVE-2008-6890 1 Codetoad 1 Asp Forum Script 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter.