Vulnerabilities (CVE)

Filtered by CWE-89
Total 17789 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-4780 1 Enanocms 1 Enano Cms 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the check_banlist function in includes/sessions.php in Enano CMS 1.1.7pl1; 1.0.6pl2; and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2 allows remote attackers to execute arbitrary SQL commands via the email parameter to index.php. NOTE: some of these details are obtained from third party information.
CVE-2009-4730 1 X10media 1 Adult Script 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in report.php in x10 Adult Media Script 1.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-3601 1 Invisionpower 1 Ibphotohost 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands via the img parameter.
CVE-2011-4811 1 Bst 1 Bestshoppro 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands via the str parameter.
CVE-2009-4783 1 Mntechsolutions 1 Theeta Cms 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php.
CVE-2010-4849 1 Alibabaclone 1 Alibaba Clone B2b 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in countrydetails.php in Alibaba Clone B2B 3.4 allows remote attackers to execute arbitrary SQL commands via the es_id parameter.
CVE-2009-4673 1 Mole-group 1 Adult Portal Script 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in profile.php in Mole Group Adult Portal Script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
CVE-2010-1327 1 Tornadostore 1 Tornadostore 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
CVE-2012-3998 1 Sayakbanerjee 1 Sticky Notes 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to execute arbitrary SQL commands via the (1) paste id in admin/modules/mod_pastes.php or (2) show.php, (3) user id to admin/modules/mod_users.php, (4) project to list.php, or (5) session id to show.php.
CVE-2012-4060 1 Asp-dev 1 Xm Forums 2025-04-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp.
CVE-2009-4871 1 Logoshows 1 Logoshows Bbs 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in globepersonnel_forum.asp in Logoshows BBS 2.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
CVE-2013-5322 2 Jan Bednarik, Typo3 2 Cooluri, Typo3 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the CoolURI extension before 1.0.30 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2010-5049 1 Zabbix 1 Zabbix 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in events.php in Zabbix 1.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the nav_time parameter.
CVE-2009-4718 1 Gonafish 1 Webstatcaffe 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in visitorduration.php in Gonafish WebStatCaffe allows remote attackers to execute arbitrary SQL commands via the nodayshow parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2010-2923 2 Joomla, Prasanna 2 Joomla\!, Com Youtube 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.
CVE-2010-5055 1 Almnzm 1 Almnzm 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2013-5697 2 Apache, Simone Tellini 2 Http Server, Mod Accounting 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.
CVE-2010-2339 1 Subdreamer 1 Subdreamer 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.
CVE-2010-1713 1 Postnuke 1 Postnuke 2025-04-11 7.5 HIGH N/A
SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.
CVE-2010-4505 1 Injader 1 Injader 2025-04-11 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in login.php in Injader 2.4.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) un and (2) pw parameters.