Vulnerabilities (CVE)

Filtered by CWE-89
Total 16151 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-2762 1 S9y 1 Serendipity 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands via the url parameter to comment.php.
CVE-2012-6273 1 Bigantsoft 1 Bigant Im Message Server 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request.
CVE-2011-4559 1 Vtiger 1 Vtiger Crm 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.
CVE-2010-2516 1 2daybiz 1 Multi Level Marketing Software 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in 2daybiz Multi Level Marketing (MLM) Software allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) index.php and (2) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-7267 1 Boka 1 Siteengine 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-1341 1 Systemsoftware 1 Community Black Forum 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter.
CVE-2010-5001 1 Esoftpro 1 Online Contact Manager 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in view.php in esoftpro Online Contact Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-4865 1 I-escorts 2 I-escorts Agency Script, I-escorts Directory Script 2025-04-11 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.
CVE-2013-3537 1 Wesley Destailleur 1 Todoo Forum 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter.
CVE-2010-2614 1 Grafik-power 1 Grafik Cms 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in admin/admin.php in Grafik CMS 1.1.2, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit_page action.
CVE-2010-1109 1 Djayp 1 Phpmysport 2025-04-11 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) v2 parameter in a member view action, (2) v1 parameter in a news action, (3) v1 parameter in an information action, (4) v2 parameter in a team view action, (5) v2 parameter in a club view action, or (6) v2 parameter in a matches view action.
CVE-2010-4959 1 Preproject 1 Pre Podcast Portal 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2011-5234 1 Scripte24shop 1 Social Network Community 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter.
CVE-2010-0614 1 Myshell 1 Evalsmsi 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions.
CVE-2010-0950 1 Natychmiast-cms 1 Natychmiast-cms 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Natychmiast CMS allow remote attackers to execute arbitrary SQL commands via the id_str parameter to (1) index.php and (2) a_index.php.
CVE-2012-5289 1 Plogger 1 Plogger 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Plogger 1.0 RC1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) index.php or (2) gallery.php.
CVE-2009-4955 2 Thomas Hempel, Typo3 2 Th Ultracards, Typo3 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the ultraCards (th_ultracards) extension before 0.5.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2010-4937 2 Joomla, Robitbt 2 Joomla\!, Com Amblog 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the Amblog (com_amblog) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) articleid or (2) catid parameter to index.php.
CVE-2011-4569 2 Mybb, Tom K 2 Mybb, Forum Userbar Plugin 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.
CVE-2010-2015 1 Createch-group 1 Lisk Cms 2025-04-11 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php.