Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-5376 | 1 Gsi-office | 1 Winpat Portal | 2017-11-06 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to execute arbitrary SQL commands via the username field. | |||||
CVE-2015-2213 | 1 Wordpress | 1 Wordpress | 2017-11-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is mishandled after retrieval from the trash. | |||||
CVE-2015-4454 | 2 Cacti, Fedoraproject | 2 Cacti, Fedora | 2017-11-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php. | |||||
CVE-2016-10134 | 1 Zabbix | 1 Zabbix | 2017-11-04 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php. | |||||
CVE-2017-5154 | 1 Advantech | 1 Webaccess | 2017-11-03 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files. | |||||
CVE-2017-15381 | 1 Softwarepublico | 1 E-sic | 2017-10-31 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script). | |||||
CVE-2017-3221 | 1 Inmarsat | 1 Amosconnect 8 | 2017-10-29 | 5.0 MEDIUM | 9.8 CRITICAL |
Blind SQL injection in Inmarsat AmosConnect 8 login form allows remote attackers to access user credentials, including user names and passwords. | |||||
CVE-2017-15373 | 1 Softwarepublico | 1 E-sic | 2017-10-27 | 7.5 HIGH | 9.8 CRITICAL |
E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area). | |||||
CVE-2014-8621 | 1 Store Locator Project | 1 Store Locator | 2017-10-25 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php. | |||||
CVE-2008-2890 | 1 Offl | 1 Online Fantasy Football League | 2017-10-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php. | |||||
CVE-2008-5654 | 1 Myiosoft | 1 Easycalendar | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter, a different vector than CVE-2008-1344. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-2872 | 1 Aspindir | 1 Shibby Shop | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sayfa parameter. | |||||
CVE-2008-0916 | 1 Highwood Design | 1 Hwdvideoshare | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php. | |||||
CVE-2009-0426 | 1 Dmxready | 1 Classified Listings Manager | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |||||
CVE-2009-0427 | 1 Dmxready | 1 Member Directory Manager | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |||||
CVE-2009-0459 | 1 Wholehogsoftware | 1 Password Protect | 2017-10-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-6247 | 1 Scripts-for-sites | 1 Ez Top Sites | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in topsite.php in Scripts For Sites (SFS) EZ Top Sites allows remote attackers to execute arbitrary SQL commands via the ts parameter. | |||||
CVE-2008-0139 | 1 Loudblog | 1 Loudblog | 2017-10-19 | 6.8 MEDIUM | N/A |
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter. | |||||
CVE-2008-4902 | 1 Scripts Frenzy | 1 Article Publisher Pro | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter. | |||||
CVE-2008-2909 | 1 Clever Copy | 1 Clever Copy | 2017-10-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter. |