Vulnerabilities (CVE)

Filtered by CWE-89
Total 18768 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-1699 1 Desiquintans 1 Writers Block Cms 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in permalink.php in Desi Quintans Writer's Block CMS 3.8a allows remote attackers to execute arbitrary SQL commands via the PostID parameter.
CVE-2009-2639 1 Mrcgiguy 1 The Ticket System 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.
CVE-2008-1639 1 Neat Web 1 Neat-web 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php.
CVE-2008-6917 1 Exoscripts 1 Exophpdesk 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQL commands via the username (user parameter).
CVE-2009-0324 1 Bibciter 1 Bibciter 2026-04-23 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.
CVE-2008-2867 1 E-topbiz 1 Viral Dx 1 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.
CVE-2008-6874 1 Aspsiteware 1 Autodealer 2026-04-23 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQL commands via the iType parameter in (1) Auto1/type.asp or (2) auto2/type.asp.
CVE-2009-3973 1 Turnkeyarcade 1 Turnkey Arcade Script 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629.
CVE-2007-1469 1 Xigla 1 Absolute Image Gallery Xe 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
CVE-2008-6322 1 Cfmsource 1 Cfmblog 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.
CVE-2007-1250 1 Angel Learning 1 Learning Management Suite 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2670 1 Insanelysimple2 1 Isblog 2026-04-23 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.
CVE-2008-3251 1 Tpl Design 1 Tplsoccersite 2026-04-23 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the opp parameter to tampereunited/opponent.php; or the id parameter to (2) index.php, (3) player.php, (4) matchdetails.php, or (5) additionalpage.php in tampereunited/.
CVE-2008-2850 1 Drupal 1 Trailscout Module 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API.
CVE-2008-3383 1 Mojoscripts 1 Mojoauto 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action.
CVE-2009-2018 1 Jaredeckersley 1 Mycars 2026-04-23 6.8 MEDIUM N/A
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
CVE-2008-2676 1 Joomla 2 Com News Portal, Joomla 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
CVE-2008-1513 1 Danneo 1 Cms 2026-04-23 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
CVE-2009-3491 2 Joomla, Kinfusion 2 Joomla\!, Com Sportfusion 2026-04-23 7.5 HIGH N/A
SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.
CVE-2008-2652 1 Smeweb 1 Smeweb 2026-04-23 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters.