Vulnerabilities (CVE)

Filtered by CWE-89
Total 15703 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6527 1 Go4i 1 Go41.net Asp Forum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.
CVE-2008-6104 1 A4desk 1 A4desk Flash Event Calendar 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via the eventid parameter to admin/index.php.
CVE-2008-0849 2 Joomla, Mambo 2 Com Downloads, Com Downloads 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat function, a different vector than CVE-2008-0652.
CVE-2009-2451 1 Mim.infinix 1 Infinix 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the search form.
CVE-2009-0454 1 Dmxready 1 Online Notebook Manager 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. NOTE: some third parties report inability to verify this issue.
CVE-2007-0695 1 Free Lan Intra Internet Portal 1 Free Lan Intra Internet Portal 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.
CVE-2009-4540 1 Bpowerhouse 1 Mini Cms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6268 1 Sadi Samami 1 Multi Languages Webshop Online 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5590 1 Kalptaru Infotech 1 Product Sale Framework 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remote attackers to execute arbitrary SQL commands via the forum_topic_id parameter.
CVE-2008-2194 1 Deluxebb 1 Deluxebb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.
CVE-2009-2924 1 Videosbroadcastyourself 1 Videos Broadcast Yourself 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php.
CVE-2009-3246 1 Mybuxscript 1 Pts-bux 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI. NOTE: some of these details are obtained from third party information.
CVE-2009-0121 1 Goople Cms 1 Goople Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6324 1 Cfmsource 1 Cf Forum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.
CVE-2008-1640 1 Jgs-xa 1 Jgs Treffen 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the view_id parameter in an ansicht action.
CVE-2008-6458 2 Dieter Mayer, Typo3 2 Fe Address Edit, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the FE address edit for tt_address & direct mail (dmaddredit) extension 0.4.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2007-6658 1 Customcms 1 Ccms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page.
CVE-2009-0738 1 Frankmancuso 1 Auth Php 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.
CVE-2008-4744 1 Dxproscripts 1 Dxshopcart 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter.
CVE-2008-6456 2 Martin Helmich, Typo3 2 Hbook, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the HBook (h_book) extension 2.3.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.