Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2088 1 Phpforge 1 Php Forge 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.
CVE-2008-2084 2 Myarticles, Runcms 2 Myarticles, Myarticles Module 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a listarticles action.
CVE-2008-2845 1 Mybizz-classifieds 1 Mybizz-classifieds 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-2537 1 Hispah 1 Model Search 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in cat.php in HispaH Model Search allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2008-3118 1 Phpmotion 1 Phpmotion 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter.
CVE-2008-3133 1 Barenuked 1 Barenuked Cms 2017-09-29 6.8 MEDIUM N/A
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2008-3418 1 Willo 1 Trio 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3346 1 E-topbiz 1 Shopcart Dx 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL commands via the pid parameter.
CVE-2008-3200 1 Easy-script 1 Avlc Forum 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action.
CVE-2008-3861 1 Phpmyrealty 1 Phpmyrealty 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php.
CVE-2008-2278 1 Freelanceauction 1 Freelance Auction Script 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a pdetails action.
CVE-2008-3772 1 Pars4u 1 Videosharing 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
CVE-2008-2223 1 Buyscripts 1 Vshare Youtube Clone 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
CVE-2008-2870 1 Sharecms 1 Sharecms 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via the (1) eventID parameter to event_info.php and the (2) userID parameter to list_user.php.
CVE-2008-4074 1 Zanfi Solutions 1 Autodealers Cms Autonline 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
CVE-2008-2679 1 Realm Project 1 Realm Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in a kwl action to the default URI.
CVE-2008-2678 1 Telephone 1 Telephone Directory 2008 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm_data action to edit1.php and the (2) id parameter to view_more.php.
CVE-2008-2983 1 Cwh Underground 1 Demo4 Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3266 1 Softacid 1 Hotel Reservation System Multi 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attackers to execute arbitrary SQL commands via the key parameter.
CVE-2008-3377 1 Brandon Tallent 1 Phptest 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.