Vulnerabilities (CVE)

Filtered by CWE-89
Total 15565 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6016 1 Editeurscripts 1 Esfaq 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3952. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6887 1 Preprojects 1 Pre Classified Listings 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter.
CVE-2008-1639 1 Neat Web 1 Neat-web 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php.
CVE-2009-3439 1 Alienvault 1 Ossim 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document parameter to (1) repository_document.php, (2) repository_links.php, and (3) repository_editdocument.php in repository/; the (4) group parameter to policy/getpolicy.php; the name parameter to (5) host/newhostgroupform.php and (6) net/modifynetform.php; and unspecified other vectors related to the policy menu.
CVE-2009-1403 1 Creloaded 1 Cre Loaded 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL commands via the products_id parameter.
CVE-2008-5841 1 Igamingcms 1 Igaming Cms 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.
CVE-2008-6310 1 W3matter 1 Revsense 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
CVE-2007-4368 1 Ibm 1 Rational Clearquest 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
CVE-2008-6348 1 Developiteasy 1 Photo Gallery 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information.
CVE-2009-3500 1 Bpowerhouse 1 Bpgames 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php.
CVE-2008-6304 1 Xt-commerce 1 Xt-commerce 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in xt:Commerce before 3.0.4 Sp2.1, when magic_quotes_gpc is enabled and the SEO URLs are activated, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-0327 1 Fascript 1 Famp3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6180 1 Newlife Blogger 1 Newlife Blogger 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.
CVE-2008-6258 1 Quadcomm 1 Q-shop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the (1) UserID and (2) Pwd parameters. NOTE: this might be related to CVE-2004-2108.
CVE-2008-0278 1 X7 Group 1 X7 Chat 2025-04-09 6.0 MEDIUM N/A
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.
CVE-2007-5976 1 Phpmyadmin 1 Phpmyadmin 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.
CVE-2008-0675 1 The Everything Development Company 1 The Everything Development Engine 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pre-1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the node_id parameter.
CVE-2009-2359 1 Yasinkaplan 1 Tekradius 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL commands via (1) the GUI client, as demonstrated by input to the Browse Users text box in the Users tab; or (2) the command-line client, as demonstrated by a certain trcli -r command.
CVE-2007-4604 1 Dinkumsoft.com 1 Dl Paycart 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
CVE-2007-5986 1 Btiteam 1 Btitracker 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in include/functions.php in BtiTracker before 1.4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.