Vulnerabilities (CVE)

Filtered by CWE-89
Total 15612 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6487 1 Digiappz 1 Digiaffiliate 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields.
CVE-2008-4078 2 Ledgersmb, Sql-ledger 2 Ledgersmb, Sql-ledger 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2009-4561 1 Worms-league 1 Webleague 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
CVE-2009-3582 1 Sql-ledger 1 Sql-ledger 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to execute arbitrary SQL commands via the (1) id and possibly (2) db parameters in a Delete action to the output of a Vendors>Reports>Search search operation.
CVE-2008-5926 1 Asp-dev 1 Internal E-mail System 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commands via the (1) login parameter (aka user field) or the (2) password parameter (aka pass field). NOTE: some of these details are obtained from third party information.
CVE-2009-1751 1 Realtywebware 1 Realty Web-base 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4150 1 Dieselscripts 1 Diesel Joke Site 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.
CVE-2008-5365 1 Activewebsoftwares 1 Activevotes 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
CVE-2007-4653 1 Phpbb 1 Phpbb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.
CVE-2009-2598 1 Onlinegrades 1 Online Grades 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the key parameter in a resetpass action to index.php and (2) remote authenticated users to execute arbitrary SQL commands via the ADD parameter in a mailto action to parents/parents.php.
CVE-2008-0714 1 Mihalism 1 Multi Host 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL commands via the username parameter in a lost_password_go action.
CVE-2007-5122 1 Softbizscripts 1 Classifieds Plus Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6875 1 Humayun Shabbir Bhutta 1 Asp Product Catalog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.
CVE-2009-3418 1 Plume-cms 1 Plume Cms 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit_link action to manager/tools.php. NOTE: some of these details are obtained from third party information.
CVE-2009-0406 1 Community Cms 1 Community Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3185 1 Vclcomponents 1 Relative Real Estate Systems 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
CVE-2007-6291 1 Xigla 1 Absolute Banner Manager.net 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in abm.aspx in Xigla Absolute Banner Manager .NET 4.0 allows remote attackers to execute arbitrary SQL commands via the z parameter.
CVE-2008-6216 1 Bookingcentre 1 Booking System For Hotels Group 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.
CVE-2009-4203 1 Arabportal 1 Arab Portal 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header in a request to the default URI under admin/.
CVE-2009-2310 1 Bow Der Kleine 1 X-blc 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.