Vulnerabilities (CVE)

Filtered by CWE-89
Total 17851 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4386 1 Bookingcentre 1 Booking System For Hotels Group 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via the NoticiaID parameter and other unspecified vectors.
CVE-2008-1623 1 Lotus Web Studios Inc 1 Smoothflash 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-3975 1 Moagallery 1 Moa 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.
CVE-2008-5051 2 Jooblog, Joomla 2 Jooblog, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PostID parameter to index.php.
CVE-2008-2448 1 Aspindir 1 Meto Forum 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp.
CVE-2008-3445 1 Phpmyrealty 1 Phpmyrealty 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL commands via the location parameter.
CVE-2009-3632 1 Typo3 1 Typo3 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters.
CVE-2008-2412 1 Acgv.free 1 Acgv News 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-6580 1 Wallpaper 1 Wallpaper Complete Website 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.
CVE-2008-5123 1 Castillocentral 1 Ccleague 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.
CVE-2008-3038 1 Typo3 1 Address Directory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-4890 1 1st News 1 4 Professional 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-2395 2 Joomla, Joomlaworks 2 Joomla\!, Com K2 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.
CVE-2009-0543 1 Proftpd 1 Proftpd 2025-04-09 6.8 MEDIUM N/A
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.
CVE-2007-5704 1 Codewidgets 1 Online Event Registration Template 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp.
CVE-2008-0874 1 Xoops 1 Eempregos Module 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.
CVE-2008-5595 1 Aspapps 1 Asp Autodealer 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2007-5490 1 Okulumunsitesi 1 Portal 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Okul Otomasyon Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-1758 1 Kwsphp 1 Kwsphp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID parameter to index.php.
CVE-2008-4534 1 Ec-cube 1 Ec-cube 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in EC-CUBE Ver2 2.1.2a and earlier, and Ver2 RC 2.3.0-rc1 and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.