Vulnerabilities (CVE)

Filtered by CWE-89
Total 17808 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6181 2 Joomla, Mad4media 2 Joomla, Com Mad4joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php.
CVE-2008-4466 1 Vastal I-tech 1 Cosmetics Zone 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-2983 1 Cwh Underground 1 Demo4 Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-0110 1 Riotpix 1 Riotpix 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
CVE-2008-6459 1 Typo3 2 Autobeuser, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the auto BE User Registration (autobeuser) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-3382 1 Mojoscripts 1 Mojoclassifieds 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.
CVE-2007-6634 1 Netbizcity 1 Faqmasterflexplus 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to execute arbitrary SQL commands via the category_id parameter to faq.php, and unspecified other vectors involving additional scripts.
CVE-2008-6120 1 Socialengine 1 Socialengine 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the comment_secure parameter.
CVE-2007-6658 1 Customcms 1 Ccms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page.
CVE-2008-6210 1 Dream4 1 Koobi 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.
CVE-2009-3203 1 Ajsquare 1 Aj Auction Pro-oopd 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5223 1 Airvae 1 Commerce 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
CVE-2008-6242 1 Scripts-for-sites 1 Ez E-store 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execute arbitrary SQL commands via the where parameter.
CVE-2008-3718 1 Cyberbb 1 Cyberbb 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.
CVE-2009-3314 1 Eliteladders 1 Elite Gaming Ladders 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.
CVE-2008-0255 1 Igamingcms 1 Igaming Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.
CVE-2008-5208 2 Joomla, Mambo 3 Com Datsogallery, Joomla, Mambo 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
CVE-2008-6809 1 Bookingcentre 1 Booking System For Hotels Group 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter.
CVE-2008-2132 1 Systementor 1 Postcardmentor 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in step1.asp in Systementor PostcardMentor allows remote attackers to execute arbitrary SQL commands via the cat_fldAuto parameter.
CVE-2008-5928 1 Flds-script 1 Flds 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in redir.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.