Vulnerabilities (CVE)

Filtered by CWE-89
Total 17798 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3918 1 Ovidentia 1 Ovidentia 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6485 1 Softcomplex 1 Php Image Gallery 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.
CVE-2008-0908 1 Schoolwires 1 Academic Portal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to execute arbitrary SQL commands via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6381 1 Bcoos 1 Bcoos 2025-04-09 4.6 MEDIUM N/A
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.
CVE-2009-2436 1 Phponlinedatingsoftware 1 Myphpdating 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
CVE-2008-6037 1 Availscript 1 Availscript Article Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the v parameter.
CVE-2008-6796 1 Preprojects 1 Pre Real Estate Listings 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field).
CVE-2006-6095 1 Dotnetindex 1 Active News Manager 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by CVE-2006-6094.
CVE-2009-2776 1 Sellatsite.com 1 Smart Asp Survey 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2007-4810 1 Netjuke 1 Netjuke 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Netjuke 1.0-rc2 allow remote attackers to execute arbitrary SQL commands via (1) the ge_id parameter in a list.artists action to explore.php or (2) the id parameter in a show.tracks action to xml.php.
CVE-2008-2964 1 Researchguide 1 Researchguide 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in guide.php in ResearchGuide 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5977 1 Preprojects 1 Php Jobwebsite Pro 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.
CVE-2008-0881 1 Phpnuke 1 Okul Module 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.
CVE-2009-0295 1 Itlpoll 1 Itpoll 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6040 1 Agares Media 1 Arcadem Pro 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Arcadem Pro 2.700 through 2.802 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter, probably related to includes/articleblock.php.
CVE-2008-6368 1 Chipmunk Scripts 1 Chipmunk Guestbook 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter.
CVE-2008-7120 1 Mrcgiguy 1 Hot Links Sql-php 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter.
CVE-2007-6544 1 Runcms 1 Runcms 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php in modules/mydownloads/; or (4) ratelink.php, (5) modlink.php, or (6) brokenlink.php in modules/mylinks/.
CVE-2008-2189 1 Anserv 1 Auction Xl 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-6805 1 Micgr 1 Mic Blog 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in Mic_Blog 0.0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to category.php, the (2) user parameter to login.php, and the (3) site parameter to register.php.