Vulnerabilities (CVE)

Filtered by CWE-89
Total 15542 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-6138 1 Vu 1 Mass Mailer 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of these details are obtained from third party information.
CVE-2008-4055 1 Texmedia 1 Million Pixel Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.
CVE-2009-2640 1 Interlogy 1 Profile Manager 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.
CVE-2008-2395 1 Alkalinephp 1 Alkalinephp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in thread.php in AlkalinePHP 0.80.00 beta and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6950 1 Webhost-panel 1 Bankoi Webhosting Control Panel 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
CVE-2010-0322 2 Matthias Karr, Typo3 2 Mk Anydropdownmenu, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6353 1 Asp-cms 1 Asp-cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.
CVE-2008-6152 1 Sepcity 1 Faculty Portal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: this was originally reported for Lawyer Portal, which does not have a deptdisplay.asp file.
CVE-2008-1699 1 Desiquintans 1 Writers Block Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in permalink.php in Desi Quintans Writer's Block CMS 3.8a allows remote attackers to execute arbitrary SQL commands via the PostID parameter.
CVE-2009-3059 1 Allpublication 1 Jboard 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Joker Board (aka JBoard) 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) core/select.php or (2) the city parameter to top_add.inc.php, reachable through sboard.php.
CVE-2008-1426 1 Kaphotoservice 1 Kaphotoservice 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via the albumid parameter.
CVE-2008-6809 1 Bookingcentre 1 Booking System For Hotels Group 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter.
CVE-2009-3659 1 Stanback 1 Bs Counter 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in file/stats.php in BS Counter 2.5.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2008-4755 1 Pozscripts 1 Classified Auctions Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4880 1 Maran 1 Php Shop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.
CVE-2007-4922 2 Jeuxflash, Kwsphp 2 Jeuxflash Module, Kwsphp 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action to index.php. NOTE: some details are obtained from third party information.
CVE-2008-4658 1 Typo3 2 Jobcontrol, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the JobControl (dmmjobcontrol) 1.15.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6134 1 Drupal 2 Drupal, Everyblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2009-2609 2 Amotools, Joomla 2 Com Amocourse, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the amoCourse (com_amocourse) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.
CVE-2008-4746 1 Uniwin 1 Ecart Professional 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Uniwin eCart Professional 2.0.17 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) search.asp and (2) cartUtil.asp.