Vulnerabilities (CVE)

Filtered by CWE-89
Total 17830 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4200 2 Joomla, Vollmar 2 Joomla\!, Com Seminar 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.
CVE-2007-3063 1 Mealex 1 My Databook 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in diary.php in My Databook allows remote attackers to execute arbitrary SQL commands via the delete parameter.
CVE-2008-5779 1 Flds Script 1 Flds 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3345 1 Myiosoft 1 Easye-cards 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a pickup action.
CVE-2007-6004 1 Toko 1 Instan 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an artikel action or (2) the katid parameter in a produk action.
CVE-2007-6240 1 Snitz Communications 1 Snitz Forums 2000 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.
CVE-2009-2385 2 Fustrate, Simple Machines 2 Member Awards, Smf 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.
CVE-2009-3059 1 Allpublication 1 Jboard 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Joker Board (aka JBoard) 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) core/select.php or (2) the city parameter to top_add.inc.php, reachable through sboard.php.
CVE-2008-4713 1 212cafe 1 212cafeboard 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter.
CVE-2008-6452 1 Oceandir 1 Oceandir 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-4045 1 Frontaccounting 1 Frontaccounting 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) reporting/, (2) sales/, (3) sales/includes/, (4) sales/includes/db/, (5) sales/inquiry/, (6) sales/manage/, (7) sales/view/, (8) taxes/, and (9) taxes/db/.
CVE-2008-0802 2 Joomla, Mediaslide 2 Com Mediaslide, Com Mediaslide 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action.
CVE-2007-4173 1 Hunkaray Okul 1 Portaly 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in duyuruoku.asp in Hunkaray Okul Portali 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-3080.
CVE-2003-1573 1 Sun 1 J2ee 2025-04-09 10.0 HIGH N/A
The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."
CVE-2008-4620 1 Mrbs 1 Mrbs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.
CVE-2007-6373 1 Gestdown 1 Gestdown 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php.
CVE-2008-1864 1 Prozilla 1 Prozilla Freelancers 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter.
CVE-2007-1154 1 Webspell 1 Webspell 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, a different vulnerability than CVE-2006-4782.
CVE-2008-5952 1 Ktp Computer Customer Database 1 Ktp Computer Customer Database 2025-04-09 6.0 MEDIUM N/A
SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the tid parameter in a vtech action to the default URI.
CVE-2008-3355 1 Camera Life 1 Camera Life 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.