Vulnerabilities (CVE)

Filtered by CWE-89
Total 15643 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-5802 1 E-topbiz 1 Online Store 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-4377 1 Creative Mind 1 Creator Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter.
CVE-2008-0825 1 Caroline 1 Caroline 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Claroline before 1.8.9 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2007-0984 1 Aspcode.net 1 Pollmentor 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.
CVE-2009-2888 1 Phpscriptsnow 1 Hangman 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.
CVE-2008-5950 1 Aspapps 1 Template Creature 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter.
CVE-2008-0800 1 Joomla 1 Com Mcquiz 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
CVE-2009-2776 1 Sellatsite.com 1 Smart Asp Survey 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2008-0827 1 Phpnuke 1 Book 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-2671 1 Dcfm Blog 1 Dcfm Blog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in comments.php in DCFM Blog 0.9.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2444 1 Calogic 1 Calogic Calendars 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL commands via the langsel parameter.
CVE-2008-6327 1 Manzovi 1 Proquiz 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter, a different vector than CVE-2008-6312.
CVE-2008-2925 1 Valarsoft 1 Webmatic 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6115 1 Prozilla 1 Hosting Index 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083.
CVE-2009-0604 1 Php Director 1 Php Director 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.
CVE-2008-5628 1 Little Cms 1 Little Cms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands via the term parameter.
CVE-2008-0821 1 Osi Codes Inc. 1 Phplive 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attackers to execute arbitrary SQL commands via the questid parameter in an expand_question action.
CVE-2008-6462 2 Kurt Gusbeth, Typo3 2 Myquizpoll, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 0.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2007-4894 1 Wordpress 1 Wordpress 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remote attackers to execute arbitrary SQL commands via the post_type parameter to the pingback.extensions.getPingbacks method in the XMLRPC interface, and other unspecified parameters related to "early database escaping" and missing validation of "query string like parameters."
CVE-2007-5408 1 Cplinks 1 Cpdynalinks 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote attackers to execute arbitrary SQL commands via the category parameter.