Vulnerabilities (CVE)

Filtered by CWE-89
Total 17849 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6309 1 W3matter 1 Askpert 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-2447 1 Mytipper 1 Zogo Shop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-6303 1 Toursmanager 1 Tours Manager 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tourview.php in ToursManager allows remote attackers to execute arbitrary SQL commands via the tourid parameter.
CVE-2008-4379 1 Mr. Cgi Guy 1 Hot Links Sql Php 2025-04-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2008-4487 1 Atarone 1 Atarone 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-4880 1 Maran 1 Php Shop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.
CVE-2007-6670 1 Phpcredo 1 Phcdownload 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to execute arbitrary SQL commands via the string parameter.
CVE-2008-5950 1 Aspapps 1 Template Creature 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter.
CVE-2008-1639 1 Neat Web 1 Neat-web 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php.
CVE-2008-2356 1 Archangelmgt 1 Archangel Weblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbitrary SQL commands via the post_id parameter.
CVE-2008-5336 1 Bdigital Web Solutions 1 Webstudio Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via the pageid parameter.
CVE-2009-3150 1 Multi-website 1 Multi Website 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.
CVE-2008-1430 1 Iatek 1 Aspapp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.
CVE-2009-2782 2 Jfusion, Joomla 2 Com Jfusion, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
CVE-2008-1354 1 Advanced Data Solutions 1 Virtual Support Office Xp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in MyIssuesView.asp in Advanced Data Solutions Virtual Support Office-XP (VSO-XP) allows remote attackers to execute arbitrary SQL commands via the Issue_ID parameter.
CVE-2008-5490 1 Phpstore 1 Yahoo Answers 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2963 1 Myblog 1 Myblog 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php.
CVE-2008-6434 1 Blueriver 1 Sava Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to execute arbitrary SQL commands via the LinkServID parameter.
CVE-2008-3845 1 Craftysyntax 1 Crafty Syntax Live Help 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php.
CVE-2009-3334 2 Joomla, Lhacky 2 Joomla\!, Com Jinc 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.