Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-29280 1 Victor Cms Project 1 Victor Cms 2020-12-03 7.5 HIGH 9.8 CRITICAL
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
CVE-2020-29288 1 Gym Management System Project 1 Gym Management System 2020-12-03 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.
CVE-2020-29287 1 Car Rental Management System Project 1 Car Rental Management System 2020-12-03 7.5 HIGH 9.8 CRITICAL
An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.
CVE-2020-28091 1 Cxuu 1 Cxuucms 2020-12-01 5.0 MEDIUM 7.5 HIGH
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.
CVE-2020-21667 1 Fastadmin-tp6 Project 1 Fastadmin-tp6 2020-12-01 6.5 MEDIUM 7.2 HIGH
In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.
CVE-2020-28133 1 Simple Grocery Store Sales And Inventory Sales Project 1 Simple Grocery Store Sales And Inventory System 2020-12-01 7.5 HIGH 9.8 CRITICAL
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.
CVE-2020-28183 1 Water Billing System Project 1 Water Billing System 2020-12-01 10.0 HIGH 9.8 CRITICAL
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the username and password parameters to process.php.
CVE-2013-4313 1 Moodle 1 Moodle 2020-12-01 7.5 HIGH N/A
Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.
CVE-2012-3395 1 Moodle 1 Moodle 2020-12-01 6.5 MEDIUM N/A
SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.
CVE-2010-1615 1 Moodle 1 Moodle 2020-12-01 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the add_to_log function in mod/wiki/view.php in the wiki module, or (2) "data validation in some forms elements" related to lib/form/selectgroups.php.
CVE-2012-2363 1 Moodle 1 Moodle 2020-12-01 6.5 MEDIUM N/A
SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
CVE-2009-4305 1 Moodle 1 Moodle 2020-12-01 6.5 MEDIUM N/A
SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."
CVE-2020-21665 1 Fastadmin 1 Fastadmin 2020-11-30 6.5 MEDIUM 7.2 HIGH
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
CVE-2019-19876 1 Br-automation 1 Industrial Automation Aprol 2020-11-30 7.5 HIGH 9.8 CRITICAL
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006.
CVE-2020-28994 1 Karenderia Multiple Restaurant System Project 1 Karenderia Multiple Restaurant System 2020-11-30 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database.
CVE-2014-9520 1 Infinitewp 1 Infinitewp 2020-11-30 7.5 HIGH N/A
SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands via the historyID parameter.
CVE-2014-9519 1 Infinitewp 1 Infinitewp 2020-11-30 7.5 HIGH N/A
SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter.
CVE-2020-25475 1 Newsscriptphp 1 News Script Php Pro 2020-11-27 7.5 HIGH 9.8 CRITICAL
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
CVE-2020-26075 1 Cisco 1 Iot Field Network Director 2020-11-25 9.0 HIGH 8.8 HIGH
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-end database of an affected device. The vulnerability is due to insufficient input validation of REST API requests that are made to an affected device. An attacker could exploit this vulnerability by crafting malicious API requests to the affected device. A successful exploit could allow the attacker to gain access to the back-end database of the affected device.
CVE-2020-13877 1 Resourcexpress 1 Meeting Monitor 2020-11-24 7.5 HIGH 9.8 CRITICAL
SQL Injection issues in various ASPX pages of ResourceXpress Meeting Monitor 4.9 could lead to remote code execution and information disclosure.