Vulnerabilities (CVE)

Filtered by CWE-89
Total 17819 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-0863 1 Matteoiammarrone 1 S-cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6032 1 Wsn 1 Links 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-4576 2 Cmstactics, Joomla 2 Com Beeheard, Joomla\! 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to index.php.
CVE-2008-2095 3 Joomla, Mambo, Page-flip-tools 3 Com Flippingbook, Com Flippingbook, Flipping Book 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
CVE-2008-2907 1 Webchamado 1 Webchamado 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter.
CVE-2009-4060 1 Cubecart 1 Cubecart 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.
CVE-2007-0789 1 Mambo 1 Mambo 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter.
CVE-2008-6749 1 China-on-site 1 Flexphpdirectory 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters.
CVE-2009-2881 1 Artis.imag 1 Basilic 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via the idAuthor parameter to (1) index.php and possibly (2) allpubs.php in publications/.
CVE-2009-0808 1 Simple Cmms 1 Simplecmms 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in SimpleCMMS before 0.1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-3212 1 Scripteen 1 Free Image Hosting Script 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-1247 1 Acutecp.rediscussed 1 Acutecp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2009-0881 1 Josema Enzo 1 Isiajax 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-3752 1 Opial 1 Opial 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the genres_parent parameter.
CVE-2008-3943 1 Ezonescripts 1 Living Local 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.
CVE-2008-4457 1 Memht 1 Memht Portal 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php.
CVE-2009-2639 1 Mrcgiguy 1 The Ticket System 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.
CVE-2009-3063 2 Indianpulses, Joomla 2 Com Gameserver, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.
CVE-2008-5851 1 Mypbs 1 Mypbs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.
CVE-2008-5434 1 Punbb 1 Punbb 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in PunBB 1.3 and 1.3.1 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) order_by or (2) direction parameter to admin/users.php, or (3) configuration options to admin/settings.php.