Vulnerabilities (CVE)

Filtered by CWE-89
Total 17830 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6187 1 Gforge 1 Gforge 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
CVE-2009-1468 1 Icewarp 2 Email Server, Webmail Server 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.
CVE-2008-2479 1 Badongo 1 Phpfix 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php.
CVE-2008-0291 1 Hangzhou Rui-qiang 1 Richstrong Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-3706 1 Zeeways 1 Zeejobsite 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
CVE-2008-5649 1 Alstrasoft 1 Article Manager Pro 2025-04-09 10.0 HIGH N/A
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2008-3056 1 Typo3 1 Codeon Petition Extension 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Codeon Petition (cd_petition) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-0842 1 Joomla 1 Com Clasifier 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-6611 1 Abweb 1 Minimal Ablog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-4470 1 Dvbbs 1 Dvbbs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in boardrule.php in DVBBS 2.0 allows remote attackers to execute arbitrary SQL commands via the groupboardid parameter.
CVE-2008-6145 1 Typo3 2 Typo3, Wec Discussion Forum 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-3756 1 Yourfreeworld 1 Viral Marketing Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2918 1 Application Dynamics 1 Cartweaver 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3.
CVE-2008-2191 1 Postnuke Software Foundation 1 Pnencyclopedia 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_term action to index.php.
CVE-2008-5590 1 Kalptaru Infotech 1 Product Sale Framework 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remote attackers to execute arbitrary SQL commands via the forum_topic_id parameter.
CVE-2008-4039 1 Spice Classifieds 1 Spice Classifieds 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.
CVE-2009-0109 1 Riotpix 1 Riotpix 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-0682 1 Wordpress 1 Wordspew 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4154 1 Living-e 1 Webedition Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter.
CVE-2008-6632 1 Mercuryboard 1 Mercuryboard 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).