Vulnerabilities (CVE)

Filtered by CWE-89
Total 12396 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-5122 1 Softbizscripts 1 Classifieds Plus Script 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-0651 1 Pedro Santana Codice 1 Cms 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in login.php in Pedro Santana Codice CMS allows remote attackers to execute arbitrary SQL commands via the username field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-6106 1 Alstrasoft 1 E-friends 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewevent action.
CVE-2006-6349 1 Pwp Technologies 1 The Classified Ad System 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute arbitrary SQL commands via (1) the main parameter in a view action (includes/mainpage/view.asp) in default.asp or (2) a query in the search engine.
CVE-2008-1298 2 Kyantonius, Php-nuke 2 Hadith Module, Hadith Module 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter in a viewcat action to modules.php.
CVE-2007-1776 1 Design For Joomla 1 D4j Ezine 2024-02-28 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action.
CVE-2007-1897 1 Wordpress 1 Wordpress 2024-02-28 6.5 MEDIUM N/A
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.
CVE-2007-6058 1 Profilecms 1 Profilecms 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module.
CVE-2007-2230 1 Broadcom 1 Cleverpath Portal 2024-02-28 6.5 MEDIUM N/A
SQL injection vulnerability in CA Clever Path Portal allows remote authenticated users to execute limited SQL commands and retrieve arbitrary database contents via (1) the ofinterest parameter in a light search query, (2) description parameter in the advanced search query, and possibly other vectors.
CVE-2008-0934 2 Nukec, Php-nuke 2 Nukec, Nukec Module 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action.
CVE-2007-6127 1 Project Alumni 1 Project Alumni 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.
CVE-2007-6240 1 Snitz Communications 1 Snitz Forums 2000 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.
CVE-2007-6170 2 Debian, Digium 2 Debian Linux, Asterisk 2024-02-28 6.5 MEDIUM N/A
SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL commands via (1) ANI and (2) DNIS arguments.
CVE-2007-0642 1 Rbl 1 Tforum 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.
CVE-2007-6342 1 David Castro 1 Apache Authcas 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
CVE-2008-0397 1 Aflog.org 1 Aflog 2024-02-28 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.
CVE-2007-4762 1 E-smart Cart 1 E-smart Cart 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass fields, different vectors than CVE-2007-0092.
CVE-2007-4894 1 Wordpress 1 Wordpress 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query string like parameters."
CVE-2008-0874 1 Xoops 1 Eempregos Module 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.
CVE-2008-0677 1 A-blog 1 A-blog 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action.