Vulnerabilities (CVE)

Filtered by CWE-89
Total 17845 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6469 1 Plaincart 1 Plaincart 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands via the p parameter.
CVE-2008-1459 4 Joomla, Joomlaitalia, Mambo and 1 more 4 Joomla, Com Alberghi, Mambo and 1 more 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.
CVE-2008-4613 1 Portalapp 1 Portalapp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
CVE-2008-2856 1 Ownrs 1 Ownrs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5333 1 Nitrotech 1 Nitrotech 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5215 1 Clanlite 1 Clanlite 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.
CVE-2008-6853 1 Netcat 1 Netcat 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands via the PollID parameter.
CVE-2008-6467 1 Dieselscripts 1 Diesel Job Site 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter.
CVE-2007-0642 1 Rbl 1 Tforum 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.
CVE-2007-4604 1 Dinkumsoft.com 1 Dl Paycart 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
CVE-2009-2034 1 Ricardo Alexandre De Oliveira Staudt 1 Yogurt 2025-04-09 6.0 MEDIUM N/A
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.
CVE-2008-3258 1 Zoph 1 Zoph 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Zoph before 0.7.0.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6114 2 E107, Mytipper 2 E107, Zogo Shop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitrary SQL commands via the product parameter.
CVE-2009-2608 1 Chatelao 1 Php Address Book 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.
CVE-2007-5222 1 Maxdev 1 Mdpro 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header.
CVE-2008-1408 1 Phpbp 1 Phpbp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in includes/functions/banners-external.php in phpBP 2 RC3 (2.204) FIX 4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a banner_out action.
CVE-2007-4207 1 Kerberosdev 1 Gallery In A Box 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin_console/index.asp in Gallery In A Box allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password field. NOTE: these fields might be associated with the txtUsername and txtPassword parameters.
CVE-2008-0735 1 Auracms 1 Auracms 2025-04-09 10.0 HIGH N/A
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.
CVE-2009-0727 1 Tony Iha Kazungu 1 Taifajobs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.
CVE-2007-5996 1 Softbizscripts 1 Link Directory Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449.