Vulnerabilities (CVE)

Filtered by CWE-89
Total 17789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-5212 1 Intelliants 1 Subrion Cms 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL commands via the (1) user name or (2) password field.
CVE-2010-4143 1 Phpcheckz 1 Phpcheckz 2025-04-11 6.8 MEDIUM N/A
SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-2516 1 2daybiz 1 Multi Level Marketing Software 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in 2daybiz Multi Level Marketing (MLM) Software allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) index.php and (2) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2010-4957 2 Nadine Schwingler, Typo3 2 Ke Questionnaire, Typo3 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2010-2922 1 Ali Kenan 1 Aky Blog 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2011-2080 1 Inventivetec 1 Mediacast 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in MediaCAST 8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) a CP_ENLARGESTYLE cookie to the default URI under inventivex/managetraining/ or (2) unspecified input to authenticate_ad_setup_finished.cfm.
CVE-2013-3523 1 Gajennings 1 This 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in This HTML Is Simple (THIS) before 1.2.4 allows remote to execute arbitrary SQL commands via vectors related to op=page&id= in the URL.
CVE-2010-2135 1 Hazelpress 1 Hazelpress 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.
CVE-2010-1300 1 Yamamah 1 Yamamah 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbitrary SQL commands via the calbums parameter.
CVE-2012-4260 1 Hccgmbh 1 Mycare2x 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to modules/importer/mycare2x_importer.php; (5) myOpsEintrag or (6) keyword parameter in a Suchen action to modules/drg/mycare2x_proc_search.php; or (7) name_last or (8) pid parameter to modules/patient/mycare_pid.php.
CVE-2010-5061 1 Rsstatic 1 Rsstatic 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in RSStatic allows remote attackers to execute arbitrary SQL commands via the maxarticles parameter.
CVE-2009-4733 1 Supercrackmunkey 1 Simpleloginsys 2025-04-11 6.8 MEDIUM N/A
SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
CVE-2013-6875 1 Nagios 1 Nagios Xi 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
CVE-2010-3608 1 Wire Plastic Design 1 Wpquiz 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php.
CVE-2008-7301 1 Sclek 1 Jsite 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2011-5216 2 Troyef, Wordpress 2 Scorm Cloud, Wordpress 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in ajax.php in SCORM Cloud For WordPress plugin before 1.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the active parameter. NOTE: some of these details are obtained from third party information.
CVE-2011-3988 1 Lockon 1 Ec-cube 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in data/class/SC_Query.php in EC-CUBE 2.11.0 through 2.11.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2010-4400 1 Dynpg 1 Dynpg 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId parameter.
CVE-2010-2624 1 Iscripts 1 Easysnaps 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in iScripts EasySnaps 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) comment parameter to add_comments.php, (2) values parameter to tags_details.php, or (3) begin parameter to greetings.php.
CVE-2010-0764 1 Kuwaitphp 1 Esmile 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in KuwaitPHP eSmile allows remote attackers to execute arbitrary SQL commands via the cid parameter in a show action.