Total
15791 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-12254 | 1 Harmistechnology | 1 Ek Rishta | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI. | |||||
CVE-2018-12250 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL injection. | |||||
CVE-2018-12110 | 1 Portfoliocms Project | 1 Portfoliocms | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter. | |||||
CVE-2018-12055 | 1 Schools Alert Management Script Project | 1 Schools Alert Management Script | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on. | |||||
CVE-2018-12052 | 1 Schools Alert Management Script Project | 1 Schools Alert Management Script | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php. | |||||
CVE-2018-12039 | 1 Joyplus-cms Project | 1 Joyplus-cms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a select substring. | |||||
CVE-2018-11801 | 1 Apache | 1 Fineract | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table. | |||||
CVE-2018-11800 | 1 Apache | 1 Fineract | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table. | |||||
CVE-2018-11774 | 1 Apache | 1 Virtual Computing Lab | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech. | |||||
CVE-2018-11772 | 1 Apache | 1 Virtual Computing Lab | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech. | |||||
CVE-2018-11722 | 1 Wuzhicms | 1 Wuzhicms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded. | |||||
CVE-2018-11643 | 1 Dialogic | 1 Powermedia Xms | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter. | |||||
CVE-2018-11589 | 1 Centreon | 2 Centreon, Centreon Web | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the id parameter in GetXmlHost.php, the chartId parameter in ExportCSVServiceData.php, the searchCurve parameter in listComponentTemplates.php, or the host_id parameter in makeXML_ListMetrics.php. | |||||
CVE-2018-11535 | 1 Sitemakin | 1 Slac | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection. | |||||
CVE-2018-11515 | 1 Gvectors | 1 Wpforo | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. | |||||
CVE-2018-11511 | 1 Asustor | 1 Asustor Data Master | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI. | |||||
CVE-2018-11470 | 1 Iscripts | 1 Eswap | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. | |||||
CVE-2018-11444 | 1 Easyservice Billing Project | 1 Easyservice Billing | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0. | |||||
CVE-2018-11414 | 1 Bearadmin Project | 1 Bearadmin | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly. | |||||
CVE-2018-11373 | 1 Iscripts | 1 Eswap | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. |