Vulnerabilities (CVE)

Filtered by CWE-89
Total 19448 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3765 1 Discountedscripts 1 Quick Poll Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3762 1 Turnkeywebtools 1 Php Live Helper 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php.
CVE-2008-3757 1 Yourfreeworld 1 Forced Matrix Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in tr1.php in YourFreeWorld Forced Matrix Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3756 1 Yourfreeworld 1 Viral Marketing Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3755 1 Yourfreeworld 1 Classifieds 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary SQL commands via the category parameter.
CVE-2008-3754 1 Yourfreeworld 1 Stylish Text Ads Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in trl.php in YourFreeWorld Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3753 1 Yourfreeworld 1 Programs Rating Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in details.php in YourFreeWorld Programs Rating Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3752 1 Yourfreeworld 1 Ad-exchange Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3751 1 Yourfreeworld 1 Short Url And Url Tracker Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in tr.php in YourFreeWorld Short Url & Url Tracker Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3750 1 Yourfreeworld 1 Url Rotator Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in tr.php in YourFreeWorld URL Rotator Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3749 1 Yourfreeworld 1 Banner Management Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3748 1 Lbstone 2 Active Php Bookmarks, Apb 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3725 1 Yourfreeworld 1 Ad Board Script 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3724 1 Papoo 1 Papoo 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl parameter.
CVE-2008-3722 1 Fipsasp 1 Fipscms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-3720 1 Deeemm 1 Dmcms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the id vector is already covered by CVE-2007-5679.
CVE-2008-3719 1 Scripts-for-sites 1 Affiliate Directory 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action.
CVE-2008-3718 1 Cyberbb 1 Cyberbb 2026-06-16 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.
CVE-2008-3713 1 Phpbasket 1 Phpbasket 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via the pro_id parameter.
CVE-2008-3711 1 Phparcadescript 1 Phparcadescript 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.