Vulnerabilities (CVE)

Filtered by CWE-89
Total 17809 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-3669 2 Foobla, Joomla 2 Com Foobla Suggestions, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the foobla Suggestions (com_foobla_suggestions) component 1.5.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the idea_id parameter to index.php.
CVE-2007-5719 1 Minibb 1 Minibb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php.
CVE-2009-2340 1 Opial 1 Opial 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtUserName (aka User Name) parameter. NOTE: some of these details are obtained from third party information.
CVE-2007-1171 1 Nukescripts 1 Nukesentinel 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.
CVE-2007-6466 1 Freewebshop 1 Freewebshop 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter in a browse list action, or (3) the group parameter in a categories action. NOTE: it was later reported that MOG - Web Shop (MOG-WebShop), a product based on the same code, is also affected.
CVE-2008-6663 1 Phpauctions 1 Phpauctions 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0106.
CVE-2009-3417 2 Idojoomla, Joomla 2 Com Idoblog, Joomla\! 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.
CVE-2009-1622 1 Ecshop 1 Ecshop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action.
CVE-2008-0800 1 Joomla 1 Com Mcquiz 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
CVE-2008-0026 1 Cisco 2 Unified Callmanager, Unified Communications Manager 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
CVE-2009-0337 1 Katywhitton 1 Blogit\! 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2869 1 E-topbiz 1 Link Ads 1 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.
CVE-2007-6575 1 Brand039 1 Mmslamp 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the idpro parameter in a prodotti_dettaglio action.
CVE-2009-2307 1 Maxdev 2 Cwguestbook, Md-pro 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php.
CVE-2008-4374 1 Cmsbuzz 1 Cms Buzz 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the id parameter in a playgame action.
CVE-2007-6083 1 Icebb 1 Icebb 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.
CVE-2008-6889 1 Activewebsoftwares 1 Aspreferral 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
CVE-2008-5636 1 Lovedesigner 1 Lito Lite Cms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-2243 1 Aaronoutpost 1 Asp Inline Corporate Calendar 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2874 1 Softbizscripts 1 Softbiz Jokes And Funny Pics Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vector than CVE-2008-1050.