Vulnerabilities (CVE)

Filtered by CWE-89
Total 15676 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4073 1 Zanfi Solutions 1 Autodealers Cms Autonline 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action.
CVE-2009-3119 2 Php-fusion, X-iweb.ru 2 Php-fusion, Download System Msf 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.
CVE-2008-6281 1 Bluocms 1 Bluo Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-2254 1 Zen-cart 1 Zen Cart 2025-04-09 7.5 HIGH N/A
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH_INFO of password_forgotten.php, related to a "SQL Execution" issue.
CVE-2008-1788 1 Prozilla 1 Entertainers 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: some of these details are obtained from third party information.
CVE-2009-3446 2 Joomla, Rick Estrada 2 Joomla, Com Mytube 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.
CVE-2008-4046 1 Elitecms 1 Elitecms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2008-0746 2 Joomla, Mambo 2 Com Gallery, Com Gallery 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
CVE-2008-1462 1 Runcms 1 Runcms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle action.
CVE-2008-3953 1 Vastal 1 Shaadi Zone 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter.
CVE-2008-3189 1 Dreamlevels 1 Dreamnews Manager 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-4360 2 Handcoders, Xoops 2 Content Module, Xoops 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2009-3217 1 Wiccle 1 Iwiccle 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.
CVE-2008-6379 1 Mxmania 1 Gallery Mx 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2009-3063 2 Indianpulses, Joomla 2 Com Gameserver, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.
CVE-2007-4603 1 Altercoder 1 Acg News 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action.
CVE-2009-2639 1 Mrcgiguy 1 The Ticket System 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.
CVE-2008-3784 2 Btitracker Project, Xbtitracker Project 2 Btitracker, Xbtitracker 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.
CVE-2009-1741 1 Dutchmonkey 1 Dm Filemanager 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
CVE-2008-5123 1 Castillocentral 1 Ccleague 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.