Vulnerabilities (CVE)

Filtered by CWE-89
Total 17849 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-5777 1 Cadenix 1 Cadenix 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-4886 1 Yourfreeworld 1 Shopping Cart Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.
CVE-2009-4337 2 Simon Rundell, Typo3 2 Pd Calendar Today, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2008-6691.
CVE-2007-4653 1 Phpbb 1 Phpbb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.
CVE-2008-4647 1 Sweetcms 1 Sweetcms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in sweetCMS 1.5.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2008-1298 2 Kyantonius, Php-nuke 2 Hadith Module, Hadith Module 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter in a viewcat action to modules.php.
CVE-2009-3642 1 Frontrange 1 Heat 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
CVE-2008-5559 1 Dazzlindonna 1 Postecards 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-5631 1 Activewebsoftwares 1 Active Ewebquiz 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or the (2) password parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-6622 1 Webbdomian 1 Post Card 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2009-4550 2 Joomla, Kunena 2 Joomla\!, Kunena Forum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter to index.php.
CVE-2008-6686 2 Jan Bednarik, Typo3 2 Cooluri, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in CoolURI (cooluri) 1.0.11 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
CVE-2008-6392 1 1scripts 1 Z1exchange 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-0284 1 Flaxweb 1 Flax Article Manager 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2009-0121 1 Goople Cms 1 Goople Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-0721 1 Mambo 1 Com Sermon 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands via the gid parameter.
CVE-2008-4459 1 Extrovert Software 1 Thyme 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-6333 1 Matthew General 1 Rss Simple News 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the pid parameter.
CVE-2008-2096 1 Backlinkspider 1 Backlink Spider 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to a site-specific component name such as link.php or backlinkspider.php.
CVE-2007-5630 1 Bbsprocess 1 Bbportals 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a tnews action.