Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-4060 | 1 Asp-dev | 1 Xm Forums | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp. | |||||
CVE-2012-4772 | 1 Intelliants | 1 Subrion Cms | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL commands via the plan_id parameter. | |||||
CVE-2012-5367 | 1 Orangehrm | 1 Orangehrm | 2017-08-29 | 6.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbitrary SQL commands via the sortField parameter to (1) viewCustomers, (2) viewPayGrades, or (3) viewSystemUsers in symfony/web/index.php/admin/, as demonstrated using cross-site request forgery (CSRF) attacks. | |||||
CVE-2012-6577 | 2 Typo3, Typoheads | 2 Typo3, Formhandler | 2017-08-29 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the Formhandler extension before 1.4.1 for TYPO3 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2012-5244 | 1 Bananadance | 1 Banana Dance | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php. | |||||
CVE-2012-4996 | 1 Rivetcode | 1 Rivettracker | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php. | |||||
CVE-2012-6507 | 1 Jason Sexauer | 1 Churchcms | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in admin.php in ChurchCMS 0.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameters in a login action. | |||||
CVE-2012-5294 | 1 Mystorexpress | 1 Tienda Virtual | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in art_detalle.php in MyStore Xpress Tienda Virtual allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2012-6516 | 1 Shawn Bradley | 1 Php Ticket System | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via the q parameter to index.php. | |||||
CVE-2012-4056 | 1 Uiga | 1 Personal Portal | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in index2.php in Uiga Personal Portal allows remote attackers to execute arbitrary SQL commands via the p parameter. | |||||
CVE-2012-5348 | 1 Wilson Steven | 1 Mangosweb Enhanced | 2017-08-29 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in MangosWeb Enhanced 3.0.3 allows remote attackers to execute arbitrary SQL commands via the login parameter in a login action to index.php. | |||||
CVE-2012-5313 | 1 Snitz Communications | 1 Snitz Forums 2000 | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter. | |||||
CVE-2012-4925 | 1 Imgpals | 1 Img Pals Photo Host | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2012-5865 | 1 Achievo | 1 Achievo | 2017-08-29 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action. | |||||
CVE-2012-4240 | 1 Group-office | 1 Groupoffice | 2017-08-29 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter. | |||||
CVE-2012-4055 | 1 Uiga | 1 Fan Club | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via the p parameter. | |||||
CVE-2012-4282 | 1 Toocharger | 1 Trombinoscope | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2012-5290 | 1 Wcs4web | 1 Easywebrealestate | 2017-08-29 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php. | |||||
CVE-2012-6519 | 1 Diy-cms | 1 Diy-cms | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter to mod.php. | |||||
CVE-2012-1022 | 1 4homepages | 1 4images | 2017-08-29 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action. |