Vulnerabilities (CVE)

Filtered by CWE-89
Total 17802 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-0400 1 Socialengine 1 Socialengine 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
CVE-2008-6310 1 W3matter 1 Revsense 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-6941 1 Turnkeyforms 1 Web Hosting Directory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.
CVE-2008-0690 1 Joomla 1 Com Directory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action.
CVE-2008-2523 1 Raknet 1 Autopatcher Server 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Autopatcher server plugin in RakNet before 3.23 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6101 1 Ezonescripts 1 Adult Banner Exchange Website 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
CVE-2008-2914 1 Preprojects 1 Php Jobwebsite Pro 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter. NOTE: some of these details are obtained from third party information.
CVE-2009-2359 1 Yasinkaplan 1 Tekradius 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL commands via (1) the GUI client, as demonstrated by input to the Browse Users text box in the Users tab; or (2) the command-line client, as demonstrated by a certain trcli -r command.
CVE-2008-6068 2 Joomla, Web Design Hero 2 Joomla, Joomladate 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.
CVE-2007-5316 1 Softbizscripts 1 Softbiz Jobs And Recruitment Script 2025-04-09 5.0 MEDIUM N/A
SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-0787 1 Mybulletinboard 1 Mybulletinboard 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
CVE-2009-4165 2 Simple Glossar, Typo3 2 Simple Glossar, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the simple Glossar (simple_glossar) extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-5815 1 Phpalumni 1 Phpalumni 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6014 1 Rianxosencabos Cms 1 Rianxosencabos Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in scripts/links.php in Rianxosencabos CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-3327 1 Webilix 1 Wx-guestbook 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.
CVE-2008-7083 1 Revou 1 Micro Blogging Twitter Clone 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.
CVE-2008-4991 1 Ec-cube 1 Ec-cube 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in LOCKON CO.,LTD. EC-CUBE 2.3.0 and earlier, 1.4.7 and earlier, and 1.5.0-beta2 and earlier; and Community Edition 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the parameter.
CVE-2008-1789 1 Prozilla 1 Forum 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
CVE-2008-4655 1 Typo3 2 Simplesurvey, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Simple survey (simplesurvey) 1.7.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-2560 1 Fourtwosevenbb 1 427bb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via the post parameter.