Vulnerabilities (CVE)

Filtered by CWE-89
Total 19475 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-5798 1 Typo3 2 Cms Poll System Extension, Typo3 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the CMS Poll system (cms_poll) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-5797 1 Typo3 2 Advcalendar Extension, Typo3 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the advCalendar extension 0.3.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-5796 1 Typo3 2 Eluna Page Comments Extension, Typo3 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-5788 1 Domainsellerpro 1 Domain Seller Pro 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5785 1 V3chat 1 V3 Chat Profiles Dating Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
CVE-2008-5782 1 Zeeways 1 Zeematri 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
CVE-2008-5781 1 Cfagcms 1 Cfagcms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in right.php in Cant Find A Gaming CMS (CFAGCMS) 1.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the title parameter.
CVE-2008-5779 1 Flds Script 1 Flds 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5778 1 Flds Script 1 Flds 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the linkid parameter.
CVE-2008-5777 1 Cadenix 1 Cadenix 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-5775 1 Apertoblog 1 Apertoblog 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5774 1 Aspsiteware 1 Homebuilder 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp and the (2) iPro parameter to (c) detail.asp.
CVE-2008-5772 1 Aspsiteware 1 Realtylistings 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.
CVE-2008-5768 2 Sirium, Xoops 2 Am Events Module, Xoops 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5767 1 Gazatem 1 Gnews Publisher 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter.
CVE-2008-5766 1 Fascript 1 Faupload 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5751 1 Alstrasoft 1 Web Email Script Enterprise 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.
CVE-2008-5739 1 Pligg 1 Pligg Cms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url parameter.
CVE-2008-5737 1 Nodstrum 1 Mysql Calendar 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2008-5733 1 Php-fusion 2 Php-fusion, Team Impact Ti Blog System Module 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.