Vulnerabilities (CVE)

Filtered by CWE-89
Total 15555 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2816 1 O2php 1 Oxygen 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.
CVE-2008-5775 1 Apertoblog 1 Apertoblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2523 1 Raknet 1 Autopatcher Server 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Autopatcher server plugin in RakNet before 3.23 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2007-5123 1 Solidweb 1 Novus 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in notas.asp in Novus 1.0 allows remote attackers to execute arbitrary SQL commands via the nota_id parameter.
CVE-2008-6438 2 E107, E107coders 2 E107, Macguru Blog Engine Plugin 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.
CVE-2009-4198 1 Cupidsystems 1 Myminibill 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action.
CVE-2008-4487 1 Atarone 1 Atarone 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6166 2 Jmds, Joomla 2 Com Kbase, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.
CVE-2009-3117 1 Snowhall 1 Silurus System 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2008-1872 1 Comdev 1 Comdev News Publisher 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-0187 1 Spacial Audio Solutions 1 Samphpweb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.
CVE-2009-4598 2 Corephp, Joomla 2 Com Jphoto, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action to index.php.
CVE-2009-3801 1 Opendocman 1 Opendocman 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6595 1 Typo3 1 Pmk Rssnewsexport Extension 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2009-0883 1 Amunak 1 Blue Eye Cms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the BlueEyeCMS_login cookie parameter.
CVE-2009-3502 1 Bpowerhouse 1 Bpmusic 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.
CVE-2008-6038 1 Mapcal 1 Mapcal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php.
CVE-2008-5170 1 Easysitenetwork 1 Cheats Complete Website 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
CVE-2009-4399 2 Fr.simon Rundell, Typo3 2 Hs Religiousartgallery, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery) extension 0.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2007-6665 1 Netchemia 1 Oneschool 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL commands via the txtLoginID parameter.