Vulnerabilities (CVE)

Filtered by CWE-89
Total 15535 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-0109 1 Riotpix 1 Riotpix 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-0776 1 Itechscripts 1 Itechbids 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
CVE-2008-0133 1 Thomas Perez 1 Tribisur 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.
CVE-2009-3443 2 Fastballproductions, Joomla 2 Com Fastball, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.
CVE-2009-1650 1 Tenfourzero 1 Shutter 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html.
CVE-2008-1121 1 Eazyportal 1 Eazyportal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the session_vars cookie.
CVE-2009-3644 2 Joomla, Soundset 2 Joomla\!, Com Soundset 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php.
CVE-2008-1508 1 Efestech 1 E-kontor 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in EfesTech E-Kontör and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4569 1 Xigla 1 Absolute Poll Manager Xe 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to execute arbitrary SQL commands via the p parameter.
CVE-2008-2572 1 Theflashblog 1 Flashblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL commands via the articulo_id parameter.
CVE-2007-4634 1 Cisco 2 Call Manager, Unified Communications Manager 2025-04-09 9.3 HIGH N/A
Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.
CVE-2008-2340 1 News Manager 1 News Manager 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.
CVE-2008-0446 1 Julian Pawlowski 1 Lulieblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-6138 1 Vu 1 Mass Mailer 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of these details are obtained from third party information.
CVE-2008-4055 1 Texmedia 1 Million Pixel Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.
CVE-2009-2640 1 Interlogy 1 Profile Manager 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.
CVE-2008-2395 1 Alkalinephp 1 Alkalinephp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in thread.php in AlkalinePHP 0.80.00 beta and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6950 1 Webhost-panel 1 Bankoi Webhosting Control Panel 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
CVE-2010-0322 2 Matthias Karr, Typo3 2 Mk Anydropdownmenu, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6353 1 Asp-cms 1 Asp-cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.