Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2897 1 Pagesquid 1 Pagesquid Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2008-2856 1 Ownrs 1 Ownrs 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-3599 1 Openimpro 1 Openimpro 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2746 1 Gryphon 1 Gllcts2 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in login.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the detail parameter.
CVE-2008-2506 1 Simpel Side 1 Weblosning 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Simpel Side Weblosning 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) mainid and (2) id parameters to index2.php.
CVE-2008-2843 1 Doitlive 1 Cms 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter in an USUB action to default.asp and the (2) Licence[SpecialLicenseNumber] (aka LicenceId) cookie to edit/default.asp.
CVE-2008-3302 1 Tuxplanet 1 Bilboblog 2017-09-29 6.0 MEDIUM N/A
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter.
CVE-2008-2222 1 Eqdkp 1 Eqdkp 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameter.
CVE-2008-3291 1 Aprox 2 Aprox Cms Engine, Aproxengine 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2853 1 Easy Webstore 1 Easy Webstore 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in Easy Webstore 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.
CVE-2008-3598 1 Psi-labs 1 Psipuss 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.
CVE-2008-2453 1 Phpclassifiedsscript 1 Php Classifieds Script 2017-09-29 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php.
CVE-2008-2124 1 Fipsasp 1 Fipscms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter.
CVE-2008-2197 1 Miniweb2 1 Blog Writer 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.
CVE-2008-3507 1 Wogan May 1 Litenews 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
CVE-2008-2643 1 Joomla 1 Com Biblestudy 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a mediaplayer action to index.php.
CVE-2008-3026 1 Oneclick Cms 1 Oneclick Cms 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-2628 2 Joomla, Ron Liskey 2 Joomla, Com Equotes 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
CVE-2008-2996 1 Gravityboardx 1 Gravity Board X 2017-09-29 6.8 MEDIUM N/A
Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchquery parameter in a getsearch action, and the (2) board_id parameter in a viewboard action.
CVE-2008-2393 1 Entertainmentscript 1 Entertainmentscript 2017-09-29 7.5 HIGH N/A
SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.