Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-2735 | 1 Sun-jester | 1 Opennews | 2017-09-19 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | |||||
CVE-2009-3750 | 1 Santostefano Giovanni | 1 Toylog | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the idm parameter. | |||||
CVE-2009-2326 | 1 Max Kervin | 1 Kervinet Forum | 2017-09-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php. NOTE: vector 2 can be leveraged for a cross-site scripting (XSS) attack. | |||||
CVE-2009-3975 | 1 Moagallery | 1 Moa | 2017-09-19 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action. | |||||
CVE-2009-3528 | 1 Al4us | 1 Mymsg | 2017-09-19 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action. | |||||
CVE-2009-3590 | 1 Vspanel | 1 Vs Panel | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands via the Cat_ID parameter. | |||||
CVE-2009-4206 | 1 Cmsnx | 1 Million Dollar Text Links | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2009-2782 | 2 Jfusion, Joomla | 2 Com Jfusion, Joomla | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php. | |||||
CVE-2009-3246 | 1 Mybuxscript | 1 Pts-bux | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-3314 | 1 Eliteladders | 1 Elite Gaming Ladders | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter. | |||||
CVE-2009-2276 | 2 Biglle, Punbb | 2 Vote For Us Extension, Punbb | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter. | |||||
CVE-2009-2309 | 1 Codice-cms | 1 Codice Cms | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via the tag parameter. | |||||
CVE-2009-2781 | 1 Arabportal | 1 Arab Portal | 2017-09-19 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666. | |||||
CVE-2009-3252 | 1 Dave Robinson | 1 Rockbandcms | 2017-09-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters. | |||||
CVE-2009-3150 | 1 Multi-website | 1 Multi Website | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action. | |||||
CVE-2009-3116 | 1 Uiga | 1 Church Portal | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action. | |||||
CVE-2009-2230 | 1 Mybulletinboard | 1 Mybulletinboard | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter. | |||||
CVE-2009-2607 | 2 Joomla, Pinme | 2 Joomla, Com Pinboard | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php. | |||||
CVE-2009-3316 | 2 Jforjoomla, Joomla | 2 Com Jreservation, Joomla | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php. | |||||
CVE-2009-2775 | 1 Phparcadescript | 1 Phparcadescript | 2017-09-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. |