Vulnerabilities (CVE)

Filtered by CWE-89
Total 16252 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-7116 1 Webidsupport 1 Webid 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.
CVE-2009-3497 1 Vastal 1 Agent Zone 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in view_listing.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-5916 1 Phphelpdesk 1 Phphelpdesk 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the login page in phphelpdesk 0.6.16 allows remote attackers to execute arbitrary SQL commands via unspecified parameters related to the "login procedures."
CVE-2009-1049 1 Kamads 1 Bloginator 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-1982 1 Wordpress 2 Wordpress, Wpss 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.
CVE-2008-4665 1 Datingpro 1 Matchmaking 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in PG Matchmaking allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) news_read.php and (2) gifts_show.php.
CVE-2009-2892 1 Scripteen 1 Free Image Hosting Script 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie.
CVE-2008-0256 1 Matteo Binda 1 Asp Photo Gallery 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.
CVE-2009-0252 1 Enthrallweb 1 Ereservations 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.
CVE-2007-6269 1 Xigla 1 Absolute News Manager.net 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.
CVE-2008-1732 1 Predictionfootball 1 Predictionfootball 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute arbitrary SQL commands via the matchid parameter in a dupa action.
CVE-2008-2626 1 Battleblog 1 Battleblog 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in comment.asp in Battle Blog 1.25 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter.
CVE-2008-2562 1 Powerphlogger 1 Powerphlogger 2025-04-09 6.5 MEDIUM N/A
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.
CVE-2008-6881 2 Joomla, Joompolitan 2 Joomla\!, Com Livechat 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php.
CVE-2008-5295 1 Jamit Software 1 Jamit Job Board 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter.
CVE-2009-2179 1 W2b 1 Phpdatingclub 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands via the sform[day] parameter.
CVE-2008-1919 1 Yourfreeworld 1 Apartment Search Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter.
CVE-2008-4755 1 Pozscripts 1 Classified Auctions Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-1661 1 Anoldman 1 Utopic 2025-04-09 6.8 MEDIUM N/A
SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.
CVE-2008-4461 1 Vastal I-tech 1 Dating Zone 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter.