Vulnerabilities (CVE)

Filtered by CWE-89
Total 16286 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6255 1 Vbulletin 1 Vbulletin 2025-04-09 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in vBulletin 3.7.4 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) answer parameter to admincp/verify.php, (2) extension parameter in an edit action to admincp/attachmentpermission.php, and the (3) iperm parameter to admincp/image.php.
CVE-2009-3150 1 Multi-website 1 Multi Website 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.
CVE-2008-1871 1 Scriptsagent 1 Links Directory 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to execute arbitrary SQL commands via the cat_id parameter in a list action.
CVE-2009-3215 2 Joomla, Php-shop-system 2 Joomla, Ixxo Cart 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.
CVE-2008-1065 1 Xoops 1 Xm Memberstats 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arbitrary SQL commands via the (1) letter or (2) sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2763 1 Xigla 1 Absolute Live Support Xe 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in search.asp in Xigla Absolute Live Support XE 5.1 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
CVE-2009-1505 1 Drupal 2 Drupal, News Page 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field.
CVE-2008-0796 1 Nuboard 1 Nuboard 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via the ssid parameter.
CVE-2009-0299 1 Groonesworld 1 Glinks 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-1341 1 Lagarde 1 Storefront 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6780 1 Scripts-for-sites 1 Ez Affiliate 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
CVE-2008-6304 1 Xt-commerce 1 Xt-commerce 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in xt:Commerce before 3.0.4 Sp2.1, when magic_quotes_gpc is enabled and the SEO URLs are activated, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6309 1 W3matter 1 Askpert 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.
CVE-2007-4368 1 Ibm 1 Rational Clearquest 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter in a GenerateMainFrame command.
CVE-2009-2142 1 Zipstore 1 Zip Store Chat 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters.
CVE-2009-4204 1 Ringsworld 1 Flashlight Free Edition 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-4762 1 E-smart Cart 1 E-smart Cart 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass fields, different vectors than CVE-2007-0092.
CVE-2009-1500 1 Projectcms 1 Projectcms 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL commands via the sn parameter.
CVE-2008-3954 1 Alstrasoft 1 Forum Pay Per Post Exchange 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action.
CVE-2007-4714 1 Yvora 1 Yvora 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.