Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6853 1 Netcat 1 Netcat 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands via the PollID parameter.
CVE-2008-6380 1 Activewebsoftwares 1 Active Web Helpdesk 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
CVE-2009-0281 1 Warhound 1 Walking Club 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
CVE-2009-0292 1 Shop-inet 1 Shop-inet 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.
CVE-2008-6216 1 Bookingcentre 1 Booking System For Hotels Group 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.
CVE-2008-6233 1 Fivedollarscripts 1 Drinks 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Five Dollar Scripts Drinks script allows remote attackers to execute arbitrary SQL commands via the recid parameter.
CVE-2008-6245 1 Scripts-for-sites 1 Ez Biz Pro 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in track.php in Scripts For Sites (SFS) EZ BIZ PRO allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-7003 1 The-rat-cms 1 The-rat-cms 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary SQL commands via the (1) user_id and (2) password parameter.
CVE-2008-6454 1 6rbscript 1 6rbscript 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.
CVE-2008-7049 1 Natterchat 1 Natterchat 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitrary SQL commands via the (1) txtUsername parameter (aka Username) and (2) txtPassword parameter (aka Password) in a form generated by home.asp. NOTE: due to lack of details, it is not clear whether this is related to CVE-2004-2206.
CVE-2008-6213 1 Harlandscripts 1 Pro Traffic One 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the trg parameter.
CVE-2008-6429 2 Joomla, Mike Leeper 2 Joomla, Com Prayercenter 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2.php.
CVE-2008-6405 1 Greatclone 1 Hotscripts Clone 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-6286 1 Activewebsoftwares 1 Active Newsletter 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.
CVE-2009-0452 1 Onlinegrades 1 Online Grades 2017-09-29 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameter.
CVE-2008-6788 1 Minddezign 1 Photo Gallery 2017-09-29 5.1 MEDIUM N/A
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.
CVE-2008-6892 1 Peel 1 Peel 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via the rubid parameter. NOTE: this might be the same issue as CVE-2005-3572.
CVE-2008-7119 1 Webidsupport 1 Webid 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6314 1 Phpbb 2 Phpbb, Tag Board 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
CVE-2008-6198 1 Mybboard 2 Custom Pages Plugin, Mybb 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.