Vulnerabilities (CVE)

Filtered by CWE-89
Total 16216 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-5975 1 Torrentstrike 1 Torrentstrike 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in index.php in TBSource, as used in (1) TBDev and (2) TorrentStrike 0.4, allows remote authenticated users to execute arbitrary SQL commands via the choice parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-1759 2 Jeuxflash, Kwsphp 2 Jeuxflash Module, Kwsphp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php, a different vector than CVE-2007-4922.
CVE-2008-3352 1 Nersoft 1 Live Music Plus 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action.
CVE-2008-6330 1 Jaia Interactive 1 Mytopix 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the send parameter in a notes action.
CVE-2009-0454 1 Dmxready 1 Online Notebook Manager 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. NOTE: some third parties report inability to verify this issue.
CVE-2008-2013 1 Pnflashgames 1 Pnflashgames 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.
CVE-2008-3673 1 Pozscripts 1 Classified Ads 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672.
CVE-2008-4912 1 Rs Maxsoft 2 Fotogalerie, Rs Maxsoft 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
CVE-2007-4714 1 Yvora 1 Yvora 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2008-3601 1 Quicksilver Forums 1 Quicksilver Forums 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action.
CVE-2009-0106 1 Phpauctions 1 Phpauctions 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
CVE-2008-1644 1 Savas Place 1 Savas Link Manager 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-3788 1 Picturespro 1 Picturespro Photo Cart 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) qtitle, (2) qid, and (3) qyear parameters to (a) search.php, and the (4) email and (5) password parameters to (b) _login.php.
CVE-2006-7089 1 Ban 1 Ban 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in connexion.php in Ban 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5772 1 Aspsiteware 1 Realtylistings 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.
CVE-2009-2638 2 Joomla, Konze 2 Joomla, Com Akobook 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php.
CVE-2008-5270 1 Wareziz 1 Yuhhu Superstar 2008 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter.
CVE-2009-1751 1 Realtywebware 1 Realty Web-base 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5307 1 Pilot Group 1 Pg Real Roommate Finder Solution 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter. NOTE: some of these details are obtained from third party information.
CVE-2007-2571 1 Xoops 1 Wfquotes Module 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.