Vulnerabilities (CVE)

Filtered by CWE-89
Total 12885 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-1362 1 Chcounter 1 Chcounter 2024-02-28 6.8 MEDIUM N/A
SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-3356 1 Plohni 1 Image Voting 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands via the show parameter.
CVE-2008-4518 1 Fastpublish 1 Fastpublish Cms 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbitrary SQL commands via the (1) sprache parameter to index2.php and the (2) artikel parameter to index.php.
CVE-2008-1554 1 Topper 1 Toppermod 2024-02-28 6.8 MEDIUM N/A
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a non-alphanumeric first character the localita parameter, which bypasses a protection mechanism.
CVE-2009-1947 1 Newsboard 1 Unclassified Newsboard 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686.
CVE-2009-0459 1 Wholehogsoftware 1 Password Protect 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.
CVE-2009-2014 1 Joomla 2 Com School, Joomla 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the classid parameter in a showclass action to index.php.
CVE-2008-4161 1 Assetman 1 Assetman 2024-02-28 6.8 MEDIUM N/A
SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.
CVE-2009-4200 2 Joomla, Vollmar 2 Joomla\!, Com Seminar 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.
CVE-2008-6460 2 Mirko Werner, Typo3 2 Mw Random Objects, Typo3 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the Simple Random Objects (mw_random_objects) extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-5974 1 Activewebsoftwares 1 Active Price Comparison 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.
CVE-2008-7097 1 Qsoft-inc 1 K-rate 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id variable in includes/functions.php, and (4) unspecified variables in modules/chat.php, as demonstrated via the (a) show parameter in an online action to index.php; (b) PATH_INTO to the room/ handler; (c) image and (d) id parameters in a vote action to index.php; (e) PATH_INFO to the blog/ handler; and (f) id parameter in a blog_edit action to index.php.
CVE-2008-5599 1 Merlix 1 Teamworx Server 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL commands via the password parameter (aka passwd field) in a login action. NOTE: some of these details are obtained from third party information.
CVE-2009-2789 2 Joomla, Permis 2 Joomla, Com Groups 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the Permis (com_groups) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6026 1 Bluecube 1 Bluecube Cms 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in tienda.php in BlueCUBE CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6595 1 Typo3 1 Pmk Rssnewsexport Extension 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2009-0295 1 Itlpoll 1 Itpoll 2024-02-28 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2865 1 Kalptaru Infotech 1 Php Site Lock 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.
CVE-2008-5607 2 Joomitaly, Joomla 2 Jmovies, Joomla 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
CVE-2008-2088 1 Phpforge 1 Php Forge 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.