Vulnerabilities (CVE)

Filtered by CWE-89
Total 16217 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-0254 1 Wavelink Media 1 Tutorialcms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.
CVE-2008-5782 1 Zeeways 1 Zeematri 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
CVE-2007-5122 1 Softbizscripts 1 Classifieds Plus Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-3801 1 Opendocman 1 Opendocman 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2135 1 Visualshapers 1 Ezcontents 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php.
CVE-2009-4375 1 Alienvault 1 Open Source Security Information Management 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter.
CVE-2008-2679 1 Realm Project 1 Realm Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in a kwl action to the default URI.
CVE-2008-6366 1 Adserversolutions 1 Affiliate Software Java 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.
CVE-2008-6181 2 Joomla, Mad4media 2 Joomla, Com Mad4joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php.
CVE-2008-6527 1 Go4i 1 Go41.net Asp Forum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.
CVE-2009-2113 1 Fretsweb Project 1 Fretsweb 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.
CVE-2007-4173 1 Hunkaray Okul 1 Portaly 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in duyuruoku.asp in Hunkaray Okul Portali 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-3080.
CVE-2008-2860 1 Aj Square 1 Aj Auction 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
CVE-2007-5991 1 Exo 1 Exophpdesk 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in ExoPHPdesk allows remote attackers to execute arbitrary SQL commands via the user parameter in a profile fn action.
CVE-2007-6269 1 Xigla 1 Absolute News Manager.net 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.
CVE-2008-6992 1 Greensql 1 Greensql Firewall 2025-04-09 7.5 HIGH N/A
GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.
CVE-2009-2036 1 Geekbill 1 Open Biller 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2008-1341 1 Lagarde 1 Storefront 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6749 1 China-on-site 1 Flexphpdirectory 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters.
CVE-2008-4754 1 Scripts-for-sites 1 Ez Forum 2025-04-09 5.8 MEDIUM N/A
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.