Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6337 2 Joomla, Joomlaapps 2 Joomla, Com Volunteer 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the job_id parameter in a jobshow action to index.php.
CVE-2008-6257 1 Openasp 1 Openasp 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idpage parameter in the pages module.
CVE-2008-6369 1 Ocean12tech 1 Contact Manager Pro 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter.
CVE-2009-0406 1 Community Cms 1 Community Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6282 1 Ortus.nirn 1 Cms Ortus 2017-09-29 6.5 MEDIUM N/A
SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the city parameter in a users_edit_pub action to index.php.
CVE-2008-6627 1 Webbdomain 1 Webshop 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2008-6466 2 Akirapowered, E107 2 Image Gallery, E107 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action.
CVE-2008-6277 1 Rakhisoftware 1 Rakhisoftware Shopping Cart 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.
CVE-2008-6721 1 Ajsquare 1 Aj Article 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).
CVE-2008-6381 1 Bcoos 1 Bcoos 2017-09-29 4.6 MEDIUM N/A
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.
CVE-2008-6452 1 Oceandir 1 Oceandir 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2009-0295 1 Itlpoll 1 Itpoll 2017-09-29 6.8 MEDIUM N/A
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6243 1 Scripts For Sites 1 Ez Hotscripts-likesite 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in showcategory.php in Scripts For Sites (SFS) Hotscripts-like Site allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2008-6464 1 Mevin 1 Basic-php-events-lister 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6467 1 Dieselscripts 1 Diesel Job Site 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter.
CVE-2008-6720 1 Deltascripts 1 Php Links 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field).
CVE-2009-0337 1 Katywhitton 1 Blogit\! 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6281 1 Bluocms 1 Bluo Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6941 1 Turnkeyforms 1 Web Hosting Directory 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.
CVE-2008-6197 1 Kwsphp 2 Galerie Module, Kwsphp 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.