Vulnerabilities (CVE)

Filtered by CWE-89
Total 17796 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-3533 1 John Beranek 1 Meeting Room Booking System 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-0355 1 Phpecho Cms 1 Phpecho Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.
CVE-2008-2425 1 Fichive 1 Fichive 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6641 1 Aspindir 1 Shader Tv 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp.
CVE-2008-6230 1 Preprojects 1 Pre Podcast Portal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5268 1 Aspportal 1 Aspportal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL commands via the Topic_Id parameter.
CVE-2008-1954 1 Webcalendar 1 Web Calendar Pro 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
CVE-2008-4746 1 Uniwin 1 Ecart Professional 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Uniwin eCart Professional 2.0.17 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) search.asp and (2) cartUtil.asp.
CVE-2009-0705 1 Powerscripts 1 Powernews 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
CVE-2008-6257 1 Openasp 1 Openasp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module.
CVE-2009-3212 1 Dimofinf 1 Infinity Script 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.
CVE-2008-4172 1 Rfaah 1 Cars-vehicles Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
CVE-2008-4203 1 Czaries 1 Czarnews 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.
CVE-2008-5212 1 Aj Square 1 Aj Auction 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
CVE-2008-6151 1 Sepcity 1 Shopping Mall 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2007-6266 1 Bcoos 1 Bcoos 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in bcoos 1.0.10 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter to modules/arcade/index.php in a show_stats action, or the lid parameter to (2) modules/myalbum/ratephoto.php or (3) modules/mylinks/ratelink.php, different vectors than CVE-2007-5104.
CVE-2007-4845 1 Rwscripts.com 1 Rw Download Lite 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute arbitrary SQL commands via the (1) dlid or (2) cid parameter.
CVE-2008-0565 1 Deltascripts 1 Php Links 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-0147 1 Smallnuke 1 Smallnuke 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.
CVE-2008-0937 2 Tinyevent, Xoops 2 Tinyevent, Tiny Event Module 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811.