Total
14188 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-2925 | 1 Openfreeway | 1 Freeway | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL commands via the ecPath parameter. | |||||
CVE-2010-1876 | 1 Ajsquare | 1 Aj Shopping Cart | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action. | |||||
CVE-2010-1270 | 1 Phpscripte24 | 1 Multi Suktions Komplett System | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | |||||
CVE-2010-2359 | 1 Activewebsoftwares | 1 Ewebquiz | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706. | |||||
CVE-2010-0800 | 2 Joomla, Joomservices | 2 Joomla\!, Com Dms | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Ossolution Team Documents Seller (aka DMS) (com_dms) component 2.5.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a view_category action to index.php. | |||||
CVE-2010-0693 | 1 Commodityrentals | 1 Trade Manager Script | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |||||
CVE-2010-1341 | 1 Systemsoftware | 1 Community Black Forum | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter. | |||||
CVE-2010-1094 | 1 Miethner-scripting | 1 Dz Erotik Auktionshaus V4rgo | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in news.php in DZ EROTIK Auktionshaus V4rgo allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2010-1109 | 1 Djayp | 1 Phpmysport | 2017-08-17 | 6.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) v2 parameter in a member view action, (2) v1 parameter in a news action, (3) v1 parameter in an information action, (4) v2 parameter in a team view action, (5) v2 parameter in a club view action, or (6) v2 parameter in a matches view action. | |||||
CVE-2010-3207 | 1 Galeriashqip | 1 Galeriashqip | 2017-08-17 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the album_id parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-2459 | 1 2daybiz | 1 Video Community Portal Script | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter. | |||||
CVE-2010-2338 | 1 Vunet | 1 Vu Web Visitor Analyst | 2017-08-17 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-0457 | 1 A3malnet | 1 Magic-portal | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2010-1134 | 1 Tiki | 1 Tikiwiki Cms\/groupware | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable. | |||||
CVE-2010-1855 | 1 Phpscripte24 | 1 Pay Per Watch \& Bid Auktions System | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | |||||
CVE-2010-1704 | 1 2daybiz | 1 Polls Script | 2017-08-17 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to execute arbitrary SQL commands via (1) the password field to login.php, (2) the login field (aka email parameter) to login.php, (3) the password field (aka pass parameter) to the default URI under admin/, and possibly (4) the login field to the default URI under admin/. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-2853 | 1 Iscripts | 1 Visualcaster | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter. | |||||
CVE-2010-1595 | 1 Ocsinventory-ng | 1 Ocs Inventory Ng | 2017-08-17 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in ocsreports/index.php in OCS Inventory NG 1.02.1 allow remote attackers to execute arbitrary SQL commands via the (1) c, (2) val_1, or (3) onglet_bis parameter. | |||||
CVE-2010-1702 | 1 Whmcs | 1 Whmcs | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter. | |||||
CVE-2010-2912 | 1 Kayako | 1 Esupport | 2017-08-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action. |