Total
15328 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-4935 | 1 Khader Abbeb | 1 Entrans | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |||||
CVE-2012-4232 | 1 Jcore | 1 Jcore | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/index.php in jCore before 1.0pre2 allows remote attackers to execute arbitrary SQL commands via the memberloginid cookie. | |||||
CVE-2011-1343 | 1 Ibm | 1 Tivoli Netcool\/omnibus | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus before 7.3.0.4 allows remote attackers to execute arbitrary SQL commands via "dynamic SQL parameters." | |||||
CVE-2012-2311 | 1 Php | 1 Php | 2025-04-11 | 7.5 HIGH | N/A |
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823. | |||||
CVE-2009-4933 | 1 Winterwebs | 1 Ezwebitor | 2025-04-11 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information. | |||||
CVE-2013-7225 | 1 Fatfreecrm | 1 Fat Free Crm | 2025-04-11 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature. | |||||
CVE-2010-4845 | 1 Mhproducts | 1 Projekt Shop | 2025-04-11 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php. | |||||
CVE-2011-0434 | 1 Gplhost | 1 Domain Technologie Control | 2025-04-11 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Domain Technologie Control (DTC) before 0.32.9 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) admin/bw_per_month.php or (2) client/bw_per_month.php. | |||||
CVE-2010-2511 | 1 2daybiz | 1 Multi Level Marketing Software | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter. | |||||
CVE-2009-4720 | 1 Gnudip | 1 Gnudip | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in cgi-bin/gnudip.cgi in GnuDIP 2.1.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-0763 | 1 Commodityrentals | 1 Vacation Rental Software | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in CommodityRentals Vacation Rental Software allows remote attackers to execute arbitrary SQL commands via the rental_id parameter in a CalendarView action. | |||||
CVE-2010-4298 | 1 Dustincowell | 1 Free Simple Software | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitrary SQL commands via the downloads_id parameter in a download_now action to index.php. | |||||
CVE-2010-0609 | 1 Novaboard | 1 Novaboard | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in header.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the nova_name cookie parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2011-4816 | 1 Ibm | 6 Maximo Asset Management, Maximo Asset Management Essentials, Maximo Service Desk and 3 more | 2025-04-11 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the KPI component in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2010-1705 | 1 Rocky.nu | 1 Modelbook | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter. | |||||
CVE-2013-6983 | 1 Cisco | 1 Unified Presence Server | 2025-04-11 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh35615. | |||||
CVE-2010-3479 | 1 Boutikone | 1 Boutikone | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |||||
CVE-2012-1029 | 1 Tubeace | 1 Tube Ace | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in mobile/search/index.php in Tube Ace (Adult PHP Tube Script) 1.6 allows remote attackers to execute arbitrary SQL commands via the q parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-0122 | 1 Timeclock-software | 1 Employee Timeclock Software | 2025-04-11 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php. | |||||
CVE-2012-0982 | 1 Vastal | 1 Agent Zone | 2025-04-11 | 7.5 HIGH | N/A |
SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter. |