Vulnerabilities (CVE)

Filtered by CWE-89
Total 16214 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2422 1 Webslider 1 Webslider 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Web Slider 0.6 allows remote attackers to execute arbitrary SQL commands via the slide parameter in a slides action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-5496 1 Pozscripts 1 Business Directory Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-4045 1 Frontaccounting 1 Frontaccounting 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) reporting/, (2) sales/, (3) sales/includes/, (4) sales/includes/db/, (5) sales/inquiry/, (6) sales/manage/, (7) sales/view/, (8) taxes/, and (9) taxes/db/.
CVE-2008-6314 1 Phpbb 2 Phpbb, Tag Board 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
CVE-2009-0534 1 Flexcms 1 Flexcms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.
CVE-2008-4785 1 E107 2 Alternate Profiles Plugin, E107 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5751 1 Alstrasoft 1 Web Email Script Enterprise 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.
CVE-2008-2554 1 Bp Blog 1 Bp Blog 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.
CVE-2007-6491 1 Kvaliitti 1 Webdoc Cms 2025-04-09 10.0 HIGH N/A
Multiple SQL injection vulnerabilities in Kvaliitti WebDoc 3.0 CMS allow remote attackers to execute arbitrary SQL commands via (1) the cat_id parameter to categories.asp; and probably (2) the document_id parameter to categories.asp, and the (3) cat_id and (4) document_id parameters to subcategory.asp.
CVE-2008-2094 1 Xoops 1 Article Module 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5490 1 Phpstore 1 Yahoo Answers 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-0604 1 Php Director 1 Php Director 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.
CVE-2008-0770 1 Ibproarcade 1 Ibproarcade 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter.
CVE-2007-5688 3 Invision Power Services, Phpbb, Sebflipper 3 Invision Power Board, Phpbb, Multi-forums Module 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters.
CVE-2008-4705 1 Phponlinedatingsoftware 1 Myphpdating 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-6202 1 Neocrome 1 Seditio 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.
CVE-2009-3203 1 Ajsquare 1 Aj Auction Pro-oopd 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-0291 1 Hangzhou Rui-qiang 1 Richstrong Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-6970 1 Ubbcentral 1 Ubb.threads 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
CVE-2008-0922 1 Php-nuke 1 Manuales 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php.