Vulnerabilities (CVE)

Filtered by CWE-89
Total 17829 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-2789 2 Joomla, Permis 2 Joomla, Com Groups 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Permis (com_groups) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-3119 2 Php-fusion, X-iweb.ru 2 Php-fusion, Download System Msf 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.
CVE-2009-1508 1 Keir Davis 1 X-forum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php.
CVE-2007-5180 1 Ohesa Emlak Portali 1 Ohesa Emlak Portali 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands via the (1) Kategori parameter in satilik.asp and the (2) Emlak parameter in detay.asp.
CVE-2008-6454 1 6rbscript 1 6rbscript 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.
CVE-2009-2915 1 2fly 1 Gift Delivery System 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action.
CVE-2008-1631 1 Emedia Office Gmbh 1 Cuteflow 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.php in CuteFlow 1.5.0 and 2.10.0 allows remote attackers to execute arbitrary SQL commands via the UserId parameter, related to the login form field in index.php.
CVE-2008-2865 1 Kalptaru Infotech 1 Php Site Lock 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.
CVE-2007-3909 1 Bandersnatch 1 Bandersnatch 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors.
CVE-2008-5813 1 Spip 1 Spip 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-2685 1 Battleblog 1 Battleblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in article.asp in Battle Blog 1.25 Build 4 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter, a different vector than CVE-2008-2626.
CVE-2008-2135 1 Visualshapers 1 Ezcontents 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php.
CVE-2008-3965 1 Mybb 1 Mybb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.4.1 allows remote attackers to execute arbitrary SQL commands via a certain editor field.
CVE-2006-6880 1 Php-update 1 Php-update 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter.
CVE-2008-2755 1 Jamm-media 1 Jamm Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6911 1 Brewblogger 1 Brewblogger 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.
CVE-2008-2847 1 Softdivision 1 Maxtrade Aoi 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Trade module in Maxtrade AIO 1.3.23 allows remote attackers to execute arbitrary SQL commands via the categori parameter in a pocategorisell action to modules.php.
CVE-2009-3970 1 Phpdirsubmit 1 Php Dir Submit 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
CVE-2009-0446 1 Web-album 1 Webalbum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2989 1 Homap 1 Homap 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via the go parameter.