Vulnerabilities (CVE)

Filtered by CWE-89
Total 11593 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-2623 1 Internetdm 1 Bed And Breakfast 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in pages.php in Internet DM Specialist Bed and Breakfast allows remote attackers to execute arbitrary SQL commands via the pp_id parameter.
CVE-2010-2622 2 Joomanager, Joomla 2 Joomanager, Joomla\! 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
CVE-2010-2616 1 Paul Mcenery 1 Php Bible Search 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in bible.php in PHP Bible Search, probably 0.99, allows remote attackers to execute arbitrary SQL commands via the chapter parameter.
CVE-2010-2611 1 I-netsolution 1 Job Search Engine Script 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in show_search_result.php in i-netsolution Job Search Engine allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
CVE-2010-2610 1 2daybiz 1 Job Site Script 2017-08-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) job_iid parameter to show_search_more.php, and (3) left_cat parameter to show_search_result.php.
CVE-2010-2609 1 2daybiz 1 Job Search Engine Script 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
CVE-2010-2462 1 Tomacero 1 Orohyip 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.
CVE-2010-2461 1 Jce-tech 1 Overstock Script 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.
CVE-2010-2460 1 Jce-tech 1 Shareasale Script 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.
CVE-2010-2459 1 2daybiz 1 Video Community Portal Script 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.
CVE-2010-2438 1 Laubrotel 1 G.cms Generator 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.
CVE-2010-2359 1 Activewebsoftwares 1 Ewebquiz 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.
CVE-2010-2357 1 Eicrasoft 1 Eicra Realestate Script 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.
CVE-2010-2354 1 Pilotgroup 1 Elms Pro 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter.
CVE-2010-2339 1 Subdreamer 1 Subdreamer 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.
CVE-2010-2338 1 Vunet 1 Vu Web Visitor Analyst 2017-08-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.
CVE-2010-2148 2 Joomla, Unisoft 2 Joomla\!, Com Mycar 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php.
CVE-2010-2142 1 Murat Ersoy 1 Cyberhost 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-2141 1 Nitropowered 1 Nitro Web Gallery 2017-08-17 7.5 HIGH N/A
SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action.
CVE-2010-2135 1 Hazelpress 1 Hazelpress 2017-08-17 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.