Vulnerabilities (CVE)

Filtered by CWE-89
Total 17829 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-4525 1 Ampjuke 1 Ampjuke 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.
CVE-2008-5075 1 Scriptsfrenzy 1 E-uploader Pro 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to (g) browser.php.
CVE-2008-7044 1 Ajsquare 1 Free Polling Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter.
CVE-2008-0833 1 Joomla 1 Com Galeria 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
CVE-2008-1714 1 Fascript 1 Faphoto 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-5166 1 Easysitenetwork 1 Riddles Website 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter.
CVE-2007-4581 1 Wbb2-addon 1 Acrotxt 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL commands via the show parameter.
CVE-2008-3498 2 Joomla, Netshinesoftware 2 Joomla\!, Com Netinvoice 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.
CVE-2009-1033 1 Deluxebb 1 Deluxebb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.
CVE-2008-3490 1 E-topbiz 1 Online Dating 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.
CVE-2008-2529 1 Advanced Links Management 1 Advanced Links Management 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbitrary SQL commands via the catId parameter.
CVE-2008-4912 1 Rs Maxsoft 2 Fotogalerie, Rs Maxsoft 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
CVE-2009-0409 1 Mzbservices 1 Max.blog 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2008-4643 1 Mywebland 1 Mystats 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
CVE-2008-5633 1 Activewebsoftwares 1 Activevotes 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
CVE-2009-2612 1 Prosmdr 1 Prosmdr 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.aspx in ProSMDR allows remote attackers to execute arbitrary SQL commands via the txtUser parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6088 2 Joomla, Joomtracker 2 Joomla, Com Joomtracker 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.
CVE-2008-1934 1 Crazy Goomba 1 Crazy Goomba 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4303 1 Php-collab 1 Php-collab 2025-04-09 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via the loginForm parameter to general/login.php, and unspecified other vectors.
CVE-2007-6223 1 Phpbb 1 Garage 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.