Vulnerabilities (CVE)

Filtered by CWE-89
Total 15688 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-5047 1 Mole Group 1 Rental Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2009-1316 1 Abk-soft 1 Ablespace 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.
CVE-2008-0510 2 Joomla, Mambo 3 Com Newsletter, Com Newsletter, Mambo 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
CVE-2008-2909 1 Clever Copy 1 Clever Copy 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter.
CVE-2009-3835 2 Joomla, Whorl Ltd 2 Joomla, Jshop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the JShop (com_jshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.
CVE-2009-3973 1 Turnkeyarcade 1 Turnkey Arcade Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629.
CVE-2008-2906 1 Webchamado 1 Webchamado 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.
CVE-2008-2900 1 Phpauction 1 Phpauction 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5957 2 Joomla, Mydyngallery 2 Joomla, Mydyngallery 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index.php.
CVE-2008-6594 1 Network-publishing 1 Rdf Newsfeed Export 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6372 1 Ocean12tech 1 Faq Manager Pro 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. NOTE: some of these details are obtained from third party information.
CVE-2008-2124 1 Fipsasp 1 Fipscms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter.
CVE-2007-6394 1 P3mbo 1 Content Injector 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter in an expand action.
CVE-2008-4458 1 E-php Scripts 1 B2b Trading Marketplace Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action.
CVE-2009-4613 1 Netartmedia 1 Real Estate Portal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-5973 1 Activewebsoftwares 1 Active Web Mail 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2008-4169 1 Iscripts 1 Easyindex 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.
CVE-2008-4709 1 Pilot Group 1 Etraining 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6837 1 Zoph 1 Zoph 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Zoph 0.7.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different issue than CVE-2008-3258. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-4605 1 Cafeengine 1 Easycafeengine 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) dish.php and (2) menu.php.