Vulnerabilities (CVE)

Filtered by CWE-89
Total 19413 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2866 1 Caupo.net 1 Cauposhop Classic 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter.
CVE-2008-2865 1 Kalptaru Infotech 1 Php Site Lock 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.
CVE-2008-2862 1 Elinestudio 1 Site Composer 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.
CVE-2008-2860 1 Aj Square 1 Aj Auction 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
CVE-2008-2858 1 Webchamado 1 Webchamado 2026-06-16 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2856 1 Ownrs 1 Ownrs 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2853 1 Easy Webstore 1 Easy Webstore 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Easy Webstore 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.
CVE-2008-2850 1 Drupal 1 Trailscout Module 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API.
CVE-2008-2847 1 Softdivision 1 Maxtrade Aoi 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in the Trade module in Maxtrade AIO 1.3.23 allows remote attackers to execute arbitrary SQL commands via the categori parameter in a pocategorisell action to modules.php.
CVE-2008-2846 1 Boatscripts 1 Boatscripts Classifieds 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL commands via the type parameter.
CVE-2008-2845 1 Mybizz-classifieds 1 Mybizz-classifieds 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-2844 1 Carscripts 1 Carscripts Classifieds 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-2843 1 Doitlive 1 Cms 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter in an USUB action to default.asp and the (2) Licence[SpecialLicenseNumber] (aka LicenceId) cookie to edit/default.asp.
CVE-2008-2837 1 Cms.brdconcept 1 Cms-brd 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter.
CVE-2008-2835 1 Igsuite 1 Igsuite 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL commands via the formid parameter.
CVE-2008-2834 1 Sidb 1 Scientific Image Database 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2823 1 Phpeasynews 1 Phpeasyblog 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.
CVE-2008-2819 1 Blognplus 1 Blognplus 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in BlognPlus (BURO GUN +) 2.5.4 and earlier MySQL and PostgreSQL editions allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-2817 1 Nitropowered 1 Nitro Web Gallery 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.
CVE-2008-2816 1 O2php 1 Oxygen 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.