Vulnerabilities (CVE)

Filtered by CWE-89
Total 17805 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-0428 1 Bloofoxcms 1 Bloofoxcms 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php.
CVE-2008-5806 1 Deltascripts 1 Php Classifieds 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.
CVE-2008-0430 1 360 Web Manager 1 360 Web Manager 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.
CVE-2008-4080 1 Stash 1 Stash 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. NOTE: some of these details are obtained from third party information.
CVE-2007-0582 1 Chernobile 1 Chernobile 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.
CVE-2008-2208 1 Maianscriptworld 1 Maian Greeting 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.
CVE-2008-2047 1 Aspindir 1 Angelo-emlak 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hpz/profil.asp and (2) hpz/prodetail.asp.
CVE-2008-2701 1 Joomla 1 Com Gameq 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page action to index.php.
CVE-2009-0287 1 Keep Toolkit 1 Keep Toolkit 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.
CVE-2009-2734 1 Achievo 1 Achievo 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.
CVE-2009-0810 1 Xatrix 1 Xguestbook 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.
CVE-2008-5037 1 Elkagroup 1 Image Gallery 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-2775 1 Phparcadescript 1 Phparcadescript 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4785 1 E107 2 Alternate Profiles Plugin, E107 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-1890 2 Azrul, Joomla 2 Jom Comment, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-6394 1 P3mbo 1 Content Injector 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter in an expand action.
CVE-2009-4475 2 Joomla, Joomlub 2 Joomla\!, Com Joomlub 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an auction edit action to index.php.
CVE-2009-2924 1 Videosbroadcastyourself 1 Videos Broadcast Yourself 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php.
CVE-2007-6058 1 Profilecms 1 Profilecms 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module.
CVE-2008-4072 1 Phsdev 1 Phsblog 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588.