Vulnerabilities (CVE)

Filtered by CWE-89
Total 15688 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4348 1 Outshine 1 Phportfolio 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in photo.php in PHPortfolio, possibly 1.3, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2651 1 Joomla 1 Com Joobb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum parameter in a forum action to index.php.
CVE-2008-5491 1 Slimcms 1 Slimcms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.
CVE-2008-2479 1 Badongo 1 Phpfix 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php.
CVE-2008-7075 1 Kalptaru Infotech 1 Stararticles 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5) article.download.php; and (6) the PATH_INFO to article.download.php. NOTE: some of these details are obtained from third party information.
CVE-2007-4810 1 Netjuke 1 Netjuke 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to execute arbitrary SQL commands via (1) the ge_id parameter in a list.artists action to explore.php or (2) the id parameter in a show.tracks action to xml.php.
CVE-2008-4374 1 Cmsbuzz 1 Cms Buzz 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the id parameter in a playgame action.
CVE-2008-2225 1 Gamecms 1 Gamecms Lite 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands via the systemId parameter.
CVE-2008-6451 1 Jportal 1 Jportal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2004-2036 or CVE-2005-3509.
CVE-2006-6073 1 Enthrallweb 1 Eshopping Cart 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.
CVE-2009-2881 1 Artis.imag 1 Basilic 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via the idAuthor parameter to (1) index.php and possibly (2) allpubs.php in publications/.
CVE-2008-6452 1 Oceandir 1 Oceandir 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-6580 1 Wallpaper 1 Wallpaper Complete Website 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.
CVE-2008-1858 1 724cms 1 724cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2008-6319 1 Cfmsource 1 Cf Calendar 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL commands via the calid parameter.
CVE-2009-3417 2 Idojoomla, Joomla 2 Com Idoblog, Joomla\! 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.
CVE-2006-6367 1 Duware 3 Dudownload, Dunews, Dupaypal 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in detail.asp in DUware DUdownload 1.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) iFile or (2) action parameter. NOTE: the iType parameter is already covered by CVE-2005-3976.
CVE-2008-3136 1 Ashopsoftware 1 Ashop Deluxe 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2009-4037 1 Frontaccounting 1 Frontaccounting 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/db/users_db.inc, and various other .inc and .php files under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6) manufacturing/, and (7) purchasing/.
CVE-2008-4523 1 Ip Reg 1 Ip Reg 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the user_name parameter.