Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-5751 | 1 Alstrasoft | 1 Web Email Script Enterprise | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action. | |||||
CVE-2008-4173 | 1 Proarcadescript | 1 Proarcadescript | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI. | |||||
CVE-2008-5196 | 1 Php-fusion | 2 Php-fusion, The Kroax Module | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter. | |||||
CVE-2008-5811 | 1 Joomla | 2 Com Paxgallery, Joomla | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php. | |||||
CVE-2008-3250 | 1 Arctictracker | 1 Arctic Issue Tracker | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL commands via the filter parameter. | |||||
CVE-2008-3191 | 1 Marcioforum | 1 Mforum | 2017-09-29 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action. | |||||
CVE-2008-2265 | 1 Emophp | 1 Emo Realty Manager | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter. | |||||
CVE-2008-3787 | 1 Nullscripts | 1 Web Directory Script | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter. | |||||
CVE-2008-2448 | 1 Aspindir | 1 Meto Forum | 2017-09-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp. | |||||
CVE-2008-2556 | 1 Hessel Brouwer | 1 Php Visit Counter | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the datespan parameter in a read action. | |||||
CVE-2008-2900 | 1 Phpauction | 1 Phpauction | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-2562 | 1 Powerphlogger | 1 Powerphlogger | 2017-09-29 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action. | |||||
CVE-2008-2569 | 1 Joomla | 1 Easybook Component | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action to index.php. | |||||
CVE-2008-2892 | 2 Feellove, Joomla | 2 Exp Shop Component, Com Expshop | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php. | |||||
CVE-2008-3132 | 1 Joomla | 1 Com Beamospetition | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php. | |||||
CVE-2008-2793 | 1 Clip-share | 1 Clipshare | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQL commands via the tid parameter. | |||||
CVE-2008-2866 | 1 Caupo.net | 1 Cauposhop Classic | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter. | |||||
CVE-2008-3585 | 1 Pozscripts | 1 Greencart Php Shopping Cart | 2017-09-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php. | |||||
CVE-2008-3309 | 1 Digiappz | 1 Digileave | 2017-09-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter. | |||||
CVE-2008-3265 | 1 Joomla | 1 Com Dtregister | 2017-09-29 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the eventId parameter in a pay_options action to index.php. |