Vulnerabilities (CVE)

Filtered by CWE-89
Total 16286 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3377 1 Brandon Tallent 1 Phptest 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.
CVE-2008-5851 1 Mypbs 1 Mypbs 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.
CVE-2008-2425 1 Fichive 1 Fichive 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-2632 1 Joomla 2 Com Acctexp, Joomla 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subscribe action to index.php.
CVE-2008-5972 1 Activewebsoftwares 1 Active Business Directory 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
CVE-2008-0934 2 Nukec, Php-nuke 2 Nukec, Nukec Module 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action.
CVE-2009-2638 2 Joomla, Konze 2 Joomla, Com Akobook 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a reply action to index.php.
CVE-2008-3123 1 Mole Group 1 Real Estate Script 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
CVE-2009-3820 2 Flagbit, Typo3 2 Fb Filebase, Typo3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Flagbit Filebase (fb_filebase) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6337 2 Joomla, Joomlaapps 2 Joomla, Com Volunteer 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the job_id parameter in a jobshow action to index.php.
CVE-2008-4524 1 Adaptcms 1 Adaptcms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.
CVE-2008-2781 1 Dzoic 1 Handshakes 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in DZOIC Handshakes 3.5 allows remote attackers to execute arbitrary SQL commands via the fname parameter in a members search action.
CVE-2008-4879 1 Maran 1 Php Shop 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.
CVE-2007-6666 1 Zenphoto 1 Zenphoto 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter.
CVE-2009-1751 1 Realtywebware 1 Realty Web-base 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4525 1 Ampjuke 1 Ampjuke 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.
CVE-2007-4837 1 Proxy Anket 1 Proxy Anket 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in anket.asp in Proxy Anket 3.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-4573 1 Aspindir 1 Munzursoft Web Portal W3 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter.
CVE-2009-3972 2 Joomla, Qproje 2 Joomla\!, Com Siirler 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php.
CVE-2008-0686 2 Joomla, Mambo 2 Com Neoreferences, Com Neoreferences 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.