Vulnerabilities (CVE)

Filtered by CWE-89
Total 17823 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-5169 1 Easysitenetwork 1 Drinks Complete Website 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter.
CVE-2008-5797 1 Typo3 2 Advcalendar Extension, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the advCalendar extension 0.3.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-4885 1 Yourfreeworld 1 Scrolling Text Ads Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-2427 1 Jobbr 1 Jobbr 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands via the emp_id parameter.
CVE-2008-5969 1 Sunbyte 1 E-flower 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2837 1 Cms.brdconcept 1 Cms-brd 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter.
CVE-2009-0427 1 Dmxready 1 Member Directory Manager 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-1746 1 Diangemilang 1 Dgnews 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
CVE-2009-1049 1 Kamads 1 Bloginator 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-6269 1 Xigla 1 Absolute News Manager.net 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.
CVE-2008-6188 1 Gforge 1 Gforge 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
CVE-2006-6747 1 Dreaxteam 1 Xt-news 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter.
CVE-2009-3336 1 Phpprobid 1 Php Pro Bid 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter.
CVE-2008-0328 1 Fascript 1 Faname 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-0290 1 Digitalhive 1 Digitalhive 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.
CVE-2009-2290 2 Joomla, Kim Eckert 2 Joomla\!, Com Bsadv 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Boy Scout Advancement (com_bsadv) component 0.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) account or (2) event task to index.php.
CVE-2008-0677 1 A-blog 1 A-blog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action.
CVE-2008-1874 1 Xpoze 1 Xpoze Pro 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to execute arbitrary SQL commands via the reed parameter.
CVE-2009-0327 1 Seraphimtech 1 Free Bible Search Php Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.
CVE-2009-4394 2 Fr.simon Rundell, Typo3 2 Ste Prayer2, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Random Prayer 2 (ste_prayer2) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.