Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-0135 | 1 Chatelao | 1 Php Address Book | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4) addressbook/register/edit_user_save.php, (5) addressbook/register/reset_password.php, (6) addressbook/register/reset_password_save.php, or (7) addressbook/register/user_add_save.php; the username parameter to (8) addressbook/register/checklogin.php or (9) addressbook/register/reset_password_save.php; the (10) lastname, (11) firstname, (12) phone, (13) permissions, or (14) notes parameter to addressbook/register/edit_user_save.php; the (15) q parameter to addressbook/register/admin_index.php; the (16) site parameter to addressbook/register/linktick.php; the (17) password parameter to addressbook/register/reset_password.php; the (18) password_hint parameter to addressbook/register/reset_password_save.php; the (19) var parameter to addressbook/register/traffic.php; or a (20) BasicLogin cookie to addressbook/register/router.php. | |||||
CVE-2012-4261 | 1 Hccgmbh | 1 Mycare2x | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in modules/patient/mycare2x_pat_info.php in myCare2x allows remote attackers to execute arbitrary SQL commands via the lang parameter. | |||||
CVE-2012-5098 | 1 J Waite | 1 Php-x-links | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Php-X-Links, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to rate.php, (2) cid parameter to view.php, or (3) t parameter to pop.php. | |||||
CVE-2012-5342 | 1 Michau Enterprises Llc | 1 Commonsense Cms | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in SenseSites CommonSense CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) special.php, (2) article.php, or (3) cat2.php. | |||||
CVE-2012-5300 | 1 Mystorexpress | 1 Tienda Virtual | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in art_catalogo.php in MyStore Xpress Tienda Virtual 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2012-4743 | 2 Eos.pe, Zeroboard | 2 Siche Search Module, Zeroboard | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in ssearch.php in Siche search module 0.5 for Zeroboard allow remote attackers to execute arbitrary SQL commands via the (1) ss, (2) sm, (3) align, or (4) category parameters. | |||||
CVE-2012-4927 | 1 Limesurvey | 1 Limesurvey | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php. | |||||
CVE-2012-3834 | 1 Alienvault | 1 Open Source Security Information Management | 2017-08-29 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OSSIM) 3.1 allows remote authenticated users to execute arbitrary SQL commands via the time[0][0] parameter. | |||||
CVE-2012-5334 | 1 Preprojects | 1 Pre Printing Press | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |||||
CVE-2012-3791 | 1 Cms-center | 1 Simple Web Content Management System | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_status.php, (3) item_detail.php, (4) item_modify.php, or (5) item_position.php in admin/; or (6) status parameter to admin/item_status.php. | |||||
CVE-2012-5288 | 1 Accomplishtechnology | 1 Phpmydirectory | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2012-6144 | 1 Typo3 | 1 Typo3 | 2017-08-29 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2012-6290 | 1 Imagecms | 1 Imagecms | 2017-08-29 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands. | |||||
CVE-2012-5297 | 1 Mavili Guestbook Project | 1 Mavili Guestbook | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2012-3820 | 1 Arialsoftware | 1 Campaign Enterprise | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp. | |||||
CVE-2012-3839 | 1 Myclientbase | 1 Myclientbase | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote attackers to execute arbitrary SQL commands via the (1) invoice_number or (2) tags parameter to index.php/invoice_search. | |||||
CVE-2012-6643 | 1 Clip-bucket | 1 Clipbucket | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the time parameter to (1) videos.php or (2) channels.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2012-5912 | 1 Pico | 1 Picopublisher | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php. | |||||
CVE-2012-5760 | 1 Ibm | 1 Netezza | 2017-08-29 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2012-4260 | 1 Hccgmbh | 1 Mycare2x | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to modules/importer/mycare2x_importer.php; (5) myOpsEintrag or (6) keyword parameter in a Suchen action to modules/drg/mycare2x_proc_search.php; or (7) name_last or (8) pid parameter to modules/patient/mycare_pid.php. |