Vulnerabilities (CVE)

Filtered by CWE-89
Total 17796 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2417 1 How2asp 1 Webboard 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary SQL commands via the qNo parameter.
CVE-2008-6366 1 Adserversolutions 1 Affiliate Software Java 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.
CVE-2008-0670 1 Joomla 1 Com Noticias 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detalhe action.
CVE-2009-2545 1 Anelectron 1 Advanced Electron Forum 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-0491 1 Fgallery Project 1 Fgallery 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.
CVE-2009-1799 1 Sebastian-thiele 1 St-gallery 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or (2) gallery_show parameter to example.php.
CVE-2008-4463 1 Vastal I-tech 1 Jobs Zone 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
CVE-2007-6391 1 Sh-news 1 Sh-news 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4660 1 Typo3 2 M1 Intern, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the M1 Intern (m1_intern) 1.0.0 extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2009-1505 1 Drupal 2 Drupal, News Page 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field.
CVE-2008-0282 1 Domphp 1 Domphp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.
CVE-2008-3513 1 Php Nuke 1 Basis Consultant Book Catalog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php.
CVE-2007-6462 1 Php Real Estate Classifieds 1 Php Real Estate Classifieds Premium Plus 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5222 1 Dvbbs 1 Dvbbs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.asp in Dvbbs 8.2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2009-3500 1 Bpowerhouse 1 Bpgames 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php.
CVE-2008-3051 1 Typo3 1 Pinboard Extension 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-0422 1 Boastmachine 1 Boastmachine 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2572 1 Theflashblog 1 Flashblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL commands via the articulo_id parameter.
CVE-2008-0853 2 Joomla, Mambo 2 Com Detail, Com Detail 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: this issue might be site-specific. If so, it should not be included in CVE.
CVE-2008-3412 1 Ecshop 1 Epshop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.