Vulnerabilities (CVE)

Filtered by CWE-89
Total 17849 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6383 1 Drupal 2 Drupal, Storm 2025-04-09 6.0 MEDIUM N/A
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-0921 1 Becontent 1 Becontent 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-5084 1 Broadcom 1 Brightstor Hierarchical Storage Manager 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opcodes (1) 0x07, (2) 0x08, (3) 0x09, (4) 0x1E, (5) 0x32, (6) 0x36, (7) 0x40, and possibly others.
CVE-2007-6393 1 Ace Image Hosting Script 1 Ace Image Hosting Script 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode.
CVE-2008-6236 1 Cafuego 1 Simple Document Management System 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6509 1 Igniterealtime 1 Openfire 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.
CVE-2008-4518 1 Fastpublish 1 Fastpublish Cms 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbitrary SQL commands via the (1) sprache parameter to index2.php and the (2) artikel parameter to index.php.
CVE-2009-1411 1 Neocrome 1 Seditio 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.
CVE-2009-4390 2 Jochen Rieger, Typo3 2 Car, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Car (car) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2009-3973 1 Turnkeyarcade 1 Turnkey Arcade Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629.
CVE-2009-0965 1 Ismail Fahmi 1 Ganesha Digital Library 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers to execute arbitrary SQL commands via the node parameter in a browse action to gdl.php.
CVE-2008-3026 1 Oneclick Cms 1 Oneclick Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2223 1 Buyscripts 1 Vshare Youtube Clone 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
CVE-2009-1651 1 2daybiz 1 Business Community Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.
CVE-2008-6380 1 Activewebsoftwares 1 Active Web Helpdesk 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
CVE-2008-1426 1 Kaphotoservice 1 Kaphotoservice 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via the albumid parameter.
CVE-2009-0279 1 Pardalcms 1 Pardalcms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-0531 1 Ontarioabandonedplaces 1 A Better Member-based Asp Photo Gallery 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
CVE-2008-4159 1 Zanfi Solutions 2 Jaw Portal, Zanfi Cms Lite 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter.
CVE-2008-2034 1 Wordpress 1 Download Monitor Plugin 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.