Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1000000 1 Ipswitch 1 Whatsup Gold 2017-11-03 6.5 MEDIUM 8.8 HIGH
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
CVE-2017-15381 1 Softwarepublico 1 E-sic 2017-10-31 7.5 HIGH 9.8 CRITICAL
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
CVE-2017-3221 1 Inmarsat 1 Amosconnect 8 2017-10-29 5.0 MEDIUM 9.8 CRITICAL
Blind SQL injection in Inmarsat AmosConnect 8 login form allows remote attackers to access user credentials, including user names and passwords.
CVE-2017-15373 1 Softwarepublico 1 E-sic 2017-10-27 7.5 HIGH 9.8 CRITICAL
E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).
CVE-2014-8621 1 Store Locator Project 1 Store Locator 2017-10-25 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.
CVE-2009-0459 1 Wholehogsoftware 1 Password Protect 2017-10-19 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.
CVE-2009-0458 1 Wholehogsoftware 1 Ware Support 2017-10-19 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.
CVE-2009-0428 1 Dmxready 1 Secure Document Library 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-0427 1 Dmxready 1 Member Directory Manager 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-0426 1 Dmxready 1 Classified Listings Manager 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2009-0333 1 Joomla 2 Com Waticketsystem, Joomla 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.
CVE-2009-0106 1 Phpauctions 1 Phpauctions 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
CVE-2008-6247 1 Scripts-for-sites 1 Ez Top Sites 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in topsite.php in Scripts For Sites (SFS) EZ Top Sites allows remote attackers to execute arbitrary SQL commands via the ts parameter.
CVE-2008-6246 1 Scripts-for-sites 1 Ez Webring 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in category.php in Scripts For Sites (SFS) EZ Webring allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-6188 1 Gforge 1 Gforge 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.
CVE-2008-6187 1 Gforge 1 Gforge 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.
CVE-2008-6150 1 Sepcity 1 Classified Ads 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter.
CVE-2008-6148 2 Joomla, Raven-worx 2 Joomla, Liveticker 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in the Live Ticker (com_liveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php.
CVE-2008-5838 1 Ephpscripts 1 E-shop Shopping Cart 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-5654 1 Myiosoft 1 Easycalendar 2017-10-19 7.5 HIGH N/A
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter, a different vector than CVE-2008-1344. NOTE: some of these details are obtained from third party information.