Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-3718 1 Cyberbb 1 Cyberbb 2017-09-29 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.
CVE-2008-2457 1 Bitmixsoft 1 Php-jokesite 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-2225 1 Gamecms 1 Gamecms Lite 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands via the systemId parameter.
CVE-2008-2277 1 Cmsnx 1 Feedback And Rating Script 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
CVE-2008-2865 1 Kalptaru Infotech 1 Php Site Lock 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.
CVE-2008-2521 1 Yabsoft 1 Mega File Hosting Script 2017-09-29 6.5 MEDIUM N/A
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.
CVE-2008-3943 1 Ezonescripts 1 Living Local 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.
CVE-2008-2918 1 Application Dynamics 1 Cartweaver 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3.
CVE-2008-3490 1 E-topbiz 1 Online Dating 2017-09-29 6.5 MEDIUM N/A
SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.
CVE-2008-3416 1 Icebb 1 Icebb 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in includes/functions.php.
CVE-2008-3412 1 Ecshop 1 Epshop 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.
CVE-2008-2893 1 Ajhyip 1 Aj Square Aj-hyip 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.
CVE-2008-2906 1 Webchamado 1 Webchamado 2017-09-29 6.8 MEDIUM N/A
SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.
CVE-2008-3944 1 Discountedscripts 1 Acg Ptp 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.
CVE-2008-2903 1 Awbs 1 Advanced Webhost Billing System 2017-09-29 6.8 MEDIUM N/A
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.
CVE-2008-2700 1 Gwm 1 Galatolo Webmanager 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3136 1 Ashopsoftware 1 Ashop Deluxe 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-2113 1 Phpeasydata 1 Phpeasydata 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-3417 1 Fipsasp 1 Fipscms Light 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.
CVE-2008-3351 1 Atomphotoblog 1 Atomphotoblog 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action.