Vulnerabilities (CVE)

Filtered by CWE-89
Total 15431 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4433 2 Rmsoft, Xoops 2 Minishop Module, Xoops 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops might allow remote attackers to execute arbitrary SQL commands via the itemsxpag parameter.
CVE-2009-3645 2 Joomla, Joomlacache 2 Joomla\!, Com Cbresumebuilder 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php.
CVE-2009-2164 1 Kjtechforce 1 Mailman 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the code parameter to activate.php or (2) the dest parameter to index.php.
CVE-2008-4886 1 Yourfreeworld 1 Shopping Cart Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.
CVE-2008-0772 2 Joomla, Mambo 2 Com Doc, Com Doc 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.
CVE-2008-3753 1 Yourfreeworld 1 Programs Rating Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in details.php in YourFreeWorld Programs Rating Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-0920 1 Open Source Security Information Management 1 Os-sim 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.
CVE-2008-4364 1 Parsagostar 1 Parsaweb Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL commands via the (1) id parameter in the "page" page and (2) txtSearch parameter in the "Search" page.
CVE-2008-1915 1 Devworx 1 Blogworx 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2753 1 Paridel 1 Pooya Site Builder 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) xslIdn parameter to (a) utils/getXsl.aspx, and the (2) part parameter to (b) getXml.aspx and (c) getXls.aspx in utils/.
CVE-2007-6292 1 Mwopen 1 E-commerce 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-6557 1 Megacheatz 1 Megacheatz 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors.
CVE-2008-3044 1 Typo3 1 News Calendar Extension 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the News Calendar (newscalendar) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-0144 1 Phprisk 1 Netrisk 2025-04-09 7.5 HIGH N/A
PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged for local file inclusion using directory traversal sequences.
CVE-2008-6460 2 Mirko Werner, Typo3 2 Mw Random Objects, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Simple Random Objects (mw_random_objects) extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2007-0642 1 Rbl 1 Tforum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.
CVE-2009-0106 1 Phpauctions 1 Phpauctions 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
CVE-2009-1411 1 Neocrome 1 Seditio 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.
CVE-2008-2862 1 Elinestudio 1 Site Composer 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.
CVE-2008-4703 1 Bosdev 1 Bosnews 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.