Total
12885 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-1065 | 1 Getpixie | 1 Pixie Cms | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-1843 | 1 Glenn Mcgurrin | 1 Flash Quiz | 2024-02-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) quiz parameter to (a) num_questions.php, (b) answers.php, (c) high_score.php, (d) high_score_web.php, (e) results_table_web.php, and (f) question.php; and the (2) order_number parameter to (g) answers.php and (h) question.php. | |||||
CVE-2008-5321 | 2 Xoops, Xoops Hocasi | 2 Xoops, Gesgaleri | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter. | |||||
CVE-2008-4706 | 1 Vbulletin | 1 Vbgooglemap | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php. | |||||
CVE-2009-0542 | 1 Proftpd Project | 1 Proftpd | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql. | |||||
CVE-2008-4904 | 1 Typosphere | 1 Typo | 2024-02-28 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_at] parameter. | |||||
CVE-2008-6376 | 1 Nexusjnr | 1 Jbook | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter). | |||||
CVE-2008-6064 | 1 Domphp | 1 Domphp | 2024-02-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the cat parameter to agenda/index.php, and unspecified other vectors. | |||||
CVE-2009-1734 | 1 Omnisoftsol | 1 Vidsharepro | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |||||
CVE-2008-4072 | 1 Phsdev | 1 Phsblog | 2024-02-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588. | |||||
CVE-2008-6391 | 1 Nexusjnr | 1 Jbook | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the username (user parameter). | |||||
CVE-2008-6812 | 1 Surat Kabar | 1 Phpwebnews | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter. | |||||
CVE-2008-3603 | 1 Vacation Rentals | 1 Vacation Rental Script | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sections action. | |||||
CVE-2009-1509 | 1 Myiosoft | 1 Ajaxportal | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |||||
CVE-2008-1639 | 1 Neat Web | 1 Neat-web | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php. | |||||
CVE-2009-3718 | 1 Davethewebguy | 1 Battle Blog | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter. | |||||
CVE-2009-0394 | 1 Ple Cms | 1 Ple Cms | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to execute arbitrary SQL commands via the school parameter. | |||||
CVE-2008-2670 | 1 Insanelysimple2 | 1 Isblog | 2024-02-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889. | |||||
CVE-2008-6348 | 1 Developiteasy | 1 Photo Gallery | 2024-02-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-6481 | 3 Joomla, Joomprod, Mambo-foundation | 3 Joomla, Com Versioning, Mambo | 2024-02-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php. |