Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2572 1 Theflashblog 1 Flashblog 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL commands via the articulo_id parameter.
CVE-2008-2565 1 Php-address Book 1 Php-address Book 2018-10-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.
CVE-2008-2554 1 Bp Blog 1 Bp Blog 2018-10-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.
CVE-2008-2510 1 Wordpress 1 Upload File Plugin 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter.
CVE-2008-2509 1 Excuse Online 1 Excuse Online 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in pwd.asp in Excuse Online allows remote attackers to execute arbitrary SQL commands via the pID parameter.
CVE-2008-2492 1 Badongo 1 Campus Bulletin Board 2018-10-11 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Campus Bulletin Board 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to post3/view.asp and the (2) review parameter to post3/book.asp.
CVE-2008-2491 1 Hotscripts 1 Ablespace 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in adv_cat.php in AbleSpace 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-2479 1 Badongo 1 Phpfix 2018-10-11 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php.
CVE-2008-2460 1 Vbulletin 1 Vbulletin 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a search action.
CVE-2008-2454 1 Joomla 1 Com Xsstream-dm 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the movie parameter to index.php.
CVE-2008-2428 1 Torrenttrader 1 Torrenttrader Classic 2018-10-11 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in TorrentTrader 1.08 Classic allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) wantusername parameter to account-signup.php, or the (3) receiver parameter to account-inbox.php in a msg action.
CVE-2008-2411 1 Sazcart 1 Sazcart 2018-10-11 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in SazCart 1.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a details action.
CVE-2008-2339 1 Turnkeywebtools 1 Sunshop Shopping Cart 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549.
CVE-2008-2301 1 Phpway 1 Kostenloses Linkmanagementscript 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) top_view.php.
CVE-2008-2286 1 Symantec 1 Altiris Deployment Solution 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.
CVE-2008-2208 1 Maianscriptworld 1 Maian Greeting 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.
CVE-2008-2205 1 Maianscriptworld 1 Maian Music 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action.
CVE-2008-2203 1 Maianscriptworld 1 Maian Search 2018-10-11 7.5 HIGH N/A
SQL injection vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action.
CVE-2008-2191 1 Postnuke Software Foundation 1 Pnencyclopedia 2018-10-11 6.8 MEDIUM N/A
SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_term action to index.php.
CVE-2008-2190 1 Romedchim International Srl 1 Online Rent Property Script 2018-10-11 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it was later reported that 5.0 and earlier are also affected.