Vulnerabilities (CVE)

Filtered by CWE-89
Total 17849 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-1661 1 Anoldman 1 Utopic 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.
CVE-2008-1220 1 Phpnuke 1 4nchat 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2009-4256 1 Truesolution 1 Alefmentor 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) cont_id and (2) courc_id parameters in a pregled action. NOTE: some of these details are obtained from third party information.
CVE-2007-5430 1 Scottmanktelow 1 Stride Cms 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant subsystem, or the (3) course or (4) provider parameter to detail.php in the Courses subsystem.
CVE-2008-0753 1 Vwar 1 Virtual War 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.
CVE-2008-0498 1 Bigware 1 Bigware Shop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the pollid parameter in a results action to main_bigware_53.php.
CVE-2009-2230 1 Mybulletinboard 1 Mybulletinboard 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.
CVE-2006-6402 1 Mystats 1 Mystats 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in mystats.php in MyStats 1.0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the details parameter.
CVE-2008-2453 1 Phpclassifiedsscript 1 Php Classifieds Script 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php.
CVE-2008-5058 1 Preproject 1 Pre Simple Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in siteadmin/loginsucess.php in Pre Simple CMS allows remote attackers to execute arbitrary SQL commands via the user parameter, as reachable from siteadmin/adminlogin.php. NOTE: some of these details are obtained from third party information.
CVE-2008-4732 2 Pressography, Wordpress 2 Wp Comment Remix Plugin, Wordpress 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the p parameter.
CVE-2008-2087 1 Softbiz 1 Web Hosting Directory Script 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.
CVE-2008-3393 1 Infomining 1 Bookmine 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter.
CVE-2008-2177 1 Php Directory Source 1 Phpdirectorysource 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in phpDirectorySource 1.1.06, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to show.php and the (2) login parameter to admin.php.
CVE-2007-5912 1 Jportal 1 Jportal Web Portal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.
CVE-2008-4373 1 Availscript 1 Availscript Jobs Portal Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execute arbitrary SQL commands via the jid parameter.
CVE-2008-5650 1 Alstrasoft 1 Webhost Directory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the pwd parameter.
CVE-2007-3652 1 Fascript 1 Faname 2025-04-09 6.8 MEDIUM 9.8 CRITICAL
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328.
CVE-2008-6077 1 Loudblog 1 Loudblog 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.
CVE-2008-2509 1 Excuse Online 1 Excuse Online 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in pwd.asp in Excuse Online allows remote attackers to execute arbitrary SQL commands via the pID parameter.