Vulnerabilities (CVE)

Filtered by CWE-89
Total 15514 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-5738 1 Punbb 1 Punbb 2025-04-09 2.1 LOW 7.2 HIGH
Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.
CVE-2009-4591 1 Secureideas 1 Base 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6394 1 Cs-cart 1 Cs-cart 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.
CVE-2008-2522 1 Haudenschilt 1 Battlenet Clan Script 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in a members action.
CVE-2009-3497 1 Vastal 1 Agent Zone 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2381 1 Gforge 1 Gforge 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
CVE-2007-6083 1 Icebb 1 Icebb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.
CVE-2008-6227 1 Preproject 1 Pre Multi-vendor Shopping Malls 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute arbitrary SQL commands via the (1) sid and (2) cid parameters.
CVE-2008-2489 1 Typo3 1 Sg Zfelib 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Library for Frontend Plugins (aka sg_zfelib) extension 1.1.512 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified "user input."
CVE-2009-4456 1 Greendesktiny 1 Green Desktiny 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-5180 1 Ohesa Emlak Portali 1 Ohesa Emlak Portali 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands via the (1) Kategori parameter in satilik.asp and the (2) Emlak parameter in detay.asp.
CVE-2008-2065 1 Yourfreeworld 1 Jokes Site Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in jokes.php in YourFreeWorld Jokes Site Script allows remote attackers to execute arbitrary SQL commands via the catagorie parameter.
CVE-2008-0256 1 Matteo Binda 1 Asp Photo Gallery 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.
CVE-2009-4217 2 Itamar Elharar, Joomla 2 Com Musicgallery, Joomla\! 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an itempage action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6150 1 Sepcity 1 Classified Ads 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2009-0528 1 Rhadrix 1 If-cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-1838 1 Bosdev 1 Bosclassifieds Ads Systems 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.
CVE-2009-3223 1 Inoutscripts 1 Inout Adserver 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
CVE-2007-5272 1 Furkan Tastan Blog 1 Furkan Tastan Blog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in kategori.asp in Furkan Tastan Blog allows remote attackers to execute arbitrary SQL commands via the id parameter in a goster kat action.
CVE-2008-4620 1 Mrbs 1 Mrbs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.