Vulnerabilities (CVE)

Filtered by CWE-89
Total 15257 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12981 1 Nexusphp 1 Nexusphp 2025-04-20 7.5 HIGH 9.8 CRITICAL
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.
CVE-2017-17590 1 Stackoverflow-clone Project 1 Stackoverflow-clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
CVE-2017-16000 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 6.5 MEDIUM 7.2 HIGH
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.php.
CVE-2017-17574 1 Care Clone Project 1 Care Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
CVE-2017-17103 1 Fiyo 1 Fiyo Cms 2025-04-20 6.5 MEDIUM 8.8 HIGH
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
CVE-2017-11412 1 Fiyo 1 Fiyo Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].
CVE-2017-9436 1 Teampass 1 Teampass 2025-04-20 7.5 HIGH 9.8 CRITICAL
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
CVE-2017-14402 1 Eyesofnetwork 1 Eyesofnetwork 2025-04-20 7.5 HIGH 9.8 CRITICAL
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/function.php.
CVE-2017-17920 1 Rubyonrails 1 Ruby On Rails 2025-04-20 6.8 MEDIUM 8.1 HIGH
SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input
CVE-2017-17572 1 Amazon Clone Project 1 Amazon Clone 2025-04-20 7.5 HIGH 9.8 CRITICAL
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
CVE-2017-8015 1 Emc 1 Appsync 2025-04-20 7.5 HIGH 9.8 CRITICAL
EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CVE-2016-2555 1 Atutor 1 Atutor 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
CVE-2017-1002014 1 Anblik 1 Image-gallery-with-slideshow 2025-04-20 7.5 HIGH 9.8 CRITICAL
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
CVE-2017-17592 1 Website Auction Marketplace Project 1 Website Auction Marketplace 2025-04-20 7.5 HIGH 9.8 CRITICAL
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
CVE-2017-15967 1 Mailing-manager 1 Mailing List Manager Pro 2025-04-20 7.5 HIGH 9.8 CRITICAL
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.
CVE-2017-5344 1 Dotcms 1 Dotcms 2025-04-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.
CVE-2016-9087 1 Exponentcms 1 Exponent Cms 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter.
CVE-2016-2034 1 Arubanetworks 1 Clearpass 2025-04-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
CVE-2017-17895 1 Basic Job Site Script Project 1 Basic Job Site Script 2025-04-20 7.5 HIGH 9.8 CRITICAL
Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.
CVE-2017-16896 1 Tt-rss 1 Tiny Tiny Rss 2025-04-20 7.5 HIGH 9.8 CRITICAL
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.