Vulnerabilities (CVE)

Filtered by CWE-89
Total 14648 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1183 1 Ibm 1 Tivoli Monitoring 2025-04-20 5.4 MEDIUM 7.5 HIGH
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.
CVE-2015-7877 1 User Dashboard Project 1 User Dashboard 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2017-11388 1 Trendmicro 1 Control Manager 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.
CVE-2017-1002004 1 Dtracker Project 1 Dtracker 2025-04-20 5.0 MEDIUM 7.5 HIGH
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
CVE-2017-16961 1 Bigtreecms 1 Bigtree Cms 2025-04-20 4.0 MEDIUM 6.5 MEDIUM
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The attack uses an admin/trees/add/process request with a crafted _tags[] parameter that is mishandled in a later admin/ajax/dashboard/approve-change request.
CVE-2016-7789 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.
CVE-2016-8341 1 Ecava 1 Integraxor 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the queries are not sanitized, the host's database could be subject to read, write, and delete commands.
CVE-2015-3637 1 Phpmybackuppro 1 Phpmybackuppro 2025-04-20 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.
CVE-2017-17899 1 Dolibarr 1 Dolibarr Erp\/crm 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.
CVE-2017-16851 1 Zohocorp 1 Manageengine Applications Manager 2025-04-20 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
CVE-2017-14843 1 Dasinfomedia 1 School Management System 2025-04-20 6.5 MEDIUM 8.8 HIGH
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
CVE-2016-10204 1 Zoneminder 1 Zoneminder 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CVE-2017-5344 1 Dotcms 1 Dotcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.
CVE-2017-9436 1 Teampass 1 Teampass 2025-04-20 7.5 HIGH 9.8 CRITICAL
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
CVE-2017-17615 1 Facebook Clone Script Project 1 Facebook Clone Script 2025-04-20 6.5 MEDIUM 8.8 HIGH
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
CVE-2017-15981 1 Geniusocean 1 Newspaper 2025-04-20 7.5 HIGH 9.8 CRITICAL
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
CVE-2017-6578 1 Mail-masta Project 1 Mail-masta 2025-04-20 6.5 MEDIUM 7.2 HIGH
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscriber_email.
CVE-2017-9429 1 Event List Project 1 Event List 2025-04-20 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.
CVE-2015-9234 1 Cfpaypal 1 Cp Contact Form With Paypal 2025-04-20 6.5 MEDIUM 7.2 HIGH
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
CVE-2015-7564 1 Teampass 1 Teampass 2025-04-20 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.