Vulnerabilities (CVE)

Filtered by CWE-89
Total 17822 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6337 1 Aspindir 1 Aspee Ziyaretci Defteri 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in giris.asp in Aspee and Dogantepe Ziyaretci Defteri allow remote attackers to execute arbitrary SQL commands via the (1) kullanici or (2) parola parameter.
CVE-2008-5198 1 Vizzed 1 Acmlmboard 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL commands via the pow parameter.
CVE-2008-0453 1 Easysitenetwork 1 Recipe Website Script 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
CVE-2008-6017 1 I-rater 1 I-rater Basic 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands via the idp parameter.
CVE-2009-4057 2 Inertialfate, Joomla 2 Com If Nexus, Joomla\! 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action to index.php.
CVE-2008-5630 1 Qualityunit 1 Post Affiliate Pro 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute arbitrary SQL commands via the umprof_status parameter.
CVE-2008-0855 2 Joomla, Mambo 2 Com Facileforms, Com Facileforms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
CVE-2009-3665 1 Nullam 1 Nullam Blog 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) i parameter or (2) v parameters in a register action.
CVE-2008-5306 1 Pilot Group 1 Pg Real Estate Solution 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: some of these details are obtained from third party information.
CVE-2008-4093 1 Yourownbux 1 Yourownbux 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter.
CVE-2008-0916 1 Highwood Design 1 Hwdvideoshare 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.
CVE-2008-5047 1 Mole Group 1 Rental Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2009-2235 1 Yourarticlesdirectory 1 Your Articles Directory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6180 1 Newlife Blogger 1 Newlife Blogger 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.
CVE-2009-1433 1 Silverstripe 1 Silverstripe 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter.
CVE-2008-5652 1 Myiosoft 1 Easybookmarker 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-2263 1 Cmsnx 1 Automated Link Exchange Portal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in linking.page.php in Automated Link Exchange Portal allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: linking.page.php is commonly renamed to link.php, links.php, etc.
CVE-2008-6263 1 Infireal 1 Saturncms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. NOTE: some of these details are obtained from third party information.
CVE-2008-0692 1 Itechscripts 1 Itechbids 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
CVE-2008-5169 1 Easysitenetwork 1 Drinks Complete Website 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter.